Impact
The Responsive iframe GoogleMap WordPress plugin is vulnerable to stored cross‑site scripting triggered by the ‘responsive_map’ shortcode. Width and height attributes are not sanitized or escaped, so an attacker who can add or edit content with a Contributor or higher role can inject arbitrary JavaScript. Once the malicious page is viewed by other users, the injected script executes with the site’s privileges, enabling attacks such as cookie theft, session hijacking, or content modification.
Affected Systems
The vulnerability affects the Responsive iframe GoogleMap plugin from Pressman Inc. All versions up to and including 1.0.2 are impacted. WordPress sites that have installed one of these releases and allow contributors or higher roles to edit content are at risk.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity and a low likelihood of exploitation is reflected by an EPSS score of less than 1%. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. Attackers must be authenticated with a Contributor or higher role, which limits the potential reach to sites whose contributors have write access. Given the moderate score and low exploitation probability, the overall risk is moderate but still actionable.
OpenCVE Enrichment