CVE-2024-0420

CVE-2024-0420: MapPress Maps for WordPress < 2.88.15 - Contributor+ Stored XSS

Vendor Unknown
Product MapPress Maps for WordPress
Published February 12, 2024
Last update October 27, 2024

CVSS base score

What the vulnerability does

01Description

The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back in the admin dashboard, allowing Contributors and above roles to perform Stored Cross-Site Scripting attacks

Key dates

02Disclosure timeline

February 12, 2024 CVE published
October 27, 2024 Record updated