Lucene search

K
cvelistWPScanCVELIST:CVE-2024-0420
HistoryFeb 12, 2024 - 4:05 p.m.

CVE-2024-0420 MapPress Maps for WordPress < 2.88.15 - Contributor+ Stored XSS

2024-02-1216:05:58
WPScan
www.cve.org
mappress
wordpress
xss
vulnerability
contributor
stored cross-site scripting

5.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back in the admin dashboard, allowing Contributors and above roles to perform Stored Cross-Site Scripting attacks

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "MapPress Maps for WordPress",
    "versions": [
      {
        "status": "affected",
        "versionType": "semver",
        "version": "0",
        "lessThan": "2.88.15"
      }
    ],
    "defaultStatus": "unaffected",
    "collectionURL": "https://wordpress.org/plugins"
  }
]

5.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

Related for CVELIST:CVE-2024-0420