Severity
5.4MEDIUM
EPSS
0.2%
top 58.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 12
Latest updateApr 17

Description

The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back in the admin dashboard, allowing Contributors and above roles to perform Stored Cross-Site Scripting attacks

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
MapPress Maps for WordPress < 2.88.15 - Contributor+ Stored XSS2024-02-12
GHSA
GHSA-q6hg-g95m-hv82: The MapPress Maps for WordPress plugin before 22024-02-12

📋Vendor Advisories

1
Red Hat
kernel: perf: RISCV: Fix panic on pmu overflow handler2024-04-17