Lucene search

K
vulnrichmentWPScanVULNRICHMENT:CVE-2024-0420
HistoryFeb 12, 2024 - 4:05 p.m.

CVE-2024-0420 MapPress Maps for WordPress < 2.88.15 - Contributor+ Stored XSS

2024-02-1216:05:58
WPScan
github.com
5
mappress maps
wordpress
vulnerability
stored xss
admin dashboard

AI Score

5.9

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back in the admin dashboard, allowing Contributors and above roles to perform Stored Cross-Site Scripting attacks

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "MapPress Maps for WordPress",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "2.88.15",
        "versionType": "semver"
      }
    ],
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected"
  }
]

AI Score

5.9

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2024-0420