Lucene search

K
wpvulndbWpvulndbWPVDB-ID:82A6EAE8-24EF-4B2D-8A4C-4F244D2C84CB
HistoryJan 12, 2024 - 12:00 a.m.

Mapster WP Maps < 1.2.39 - Contributor+ Stored XSS

2024-01-1200:00:00
wpscan.com
5
plugin
validation
escape
parameters
page
contributor role
stored cross-site scripting
security

5.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

Description The plugin does not validate and escape some of parameters before outputting them back in a page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CPENameOperatorVersion
eq1.2.39

5.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

Related for WPVDB-ID:82A6EAE8-24EF-4B2D-8A4C-4F244D2C84CB