Impact
The Easy Map Creator plugin for WordPress contains a stored cross‑site scripting flaw through the "width" parameter used in its shortcodes. Input sanitization is insufficient and output escaping is omitted, allowing an authenticated contributor or higher to inject arbitrary JavaScript. Once injected, the script runs in the context of any visitor who views the affected page, enabling defacement, cookie theft, credential harvesting, or other browser‑side attacks. This vulnerability is of the type CWE‑79 and can compromise the confidentiality and integrity of user sessions, as well as availability if malicious scripts disrupt page rendering.
Affected Systems
The vulnerability affects the Easy Map Creator plugin version 3.0.2 and all earlier releases. Users of the qrevo:Easy Map Creator WordPress plugin who have Contributor or higher access should verify the installed version; any deployment of 3.0.2 or earlier is susceptible.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation in the near term. The flaw is not listed in the CISA KEV catalog, and no public exploit samples are known. The attack requires a user with Contributor‑level access to create or edit a shortcode containing a malicious "width" attribute. If an attacker can elevate privileges or trick a contributor into submitting a payload, the stored script will execute for all visitors to the corresponding page.
OpenCVE Enrichment