CVE-2021-24383

The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue
Configurations

Configuration 1 (hide)

cpe:2.3:a:codecabin:wp_go_maps:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 05:52

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/163261/WordPress-WP-Google-Maps-8.1.11-Cross-Site-Scripting.html - Third Party Advisory, VDB Entry, Exploit () http://packetstormsecurity.com/files/163261/WordPress-WP-Google-Maps-8.1.11-Cross-Site-Scripting.html - Exploit, Third Party Advisory, VDB Entry
References () https://wpscan.com/vulnerability/1270588c-53fe-447e-b83c-1b877dc7a954 - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/1270588c-53fe-447e-b83c-1b877dc7a954 - Exploit, Third Party Advisory

Information

Published : 2021-06-21 20:15

Updated : 2024-11-21 05:52


NVD link : CVE-2021-24383

Mitre link : CVE-2021-24383

CVE.ORG link : CVE-2021-24383


JSON object : View

Products Affected

codecabin

  • wp_go_maps
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')