What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Map Plugins Basic Interactive World Map plugin <= 2.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Map Plugins Basic Interactive World Map plugin <= 2.0 versions.
Explanation of Vulnerability in Simple Terms
Basic Interactive World Map versions up to 2.0 contain a stored cross-site scripting (XSS) vulnerability. An authenticated administrator with high privileges can inject malicious scripts into the plugin's data. When other users view the affected content, the scripts execute in their browsers, potentially compromising their sessions or stealing sensitive information.
What an attacker can do
Inject malicious scripts that execute when other users view the map.
Potential impact on your site
Administrators can inject code affecting all site visitors; user sessions and data at risk.
Conditions required to exploit
Attacker must be an authenticated administrator; victim must visit the affected page.
Key dates
External resources
Related vulnerabilities