What the vulnerability does
01Description
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Jason Bobich Theme Blvd Responsive Google Maps plugin <= 1.0.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Jason Bobich Theme Blvd Responsive Google Maps plugin <= 1.0.2 versions.
Explanation of Vulnerability in Simple Terms
Theme Blvd Responsive Google Maps contains a cross-site scripting (XSS) vulnerability in versions up to 1.0.2. An authenticated user with low privileges can inject malicious scripts that execute in other users' browsers, including site administrators. The vulnerability requires user interaction—typically clicking a malicious link—and can affect the entire site if an admin is targeted.
What an attacker can do
Inject malicious scripts that run in other users' browsers, potentially stealing credentials or performing actions as those users.
Potential impact on your site
Authenticated attackers can compromise admin accounts and modify site content or settings via stored or reflected XSS.
Conditions required to exploit
Attacker must have a low-privilege account on the site; victim must click a malicious link or visit a crafted page.
Key dates
External resources
Related vulnerabilities