Impact
The vulnerability is a stored cross‑site scripting flaw that allows an attacker to inject malicious script into the web page output of the Free Google Maps plugin. A compromised page would execute the injected code in the browsers of visitors who load the affected content, potentially leading to session hijacking, defacement, or phishing attacks. The weakness is identified as CWE‑79, highlighting improper input neutralization.
Affected Systems
Agile Logix Free Google Maps is affected in all releases up to and including version 1.0.1. Any WordPress website that has this plugin installed and has not upgraded beyond that version is susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, but the EPSS score of less than 1% suggests a very low probability that the vulnerability will be exploited in the near term. The flaw is not listed in the CISA KEV catalog, and the attack would require an attacker to supply malicious input that the plugin later stores and renders, typically via an administrator who has the capability to edit the plugin’s settings.
OpenCVE Enrichment
EUVD