Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mrsaucier GoogleMapper googlemapper-2 allows Reflected XSS.This issue affects GoogleMapper: from n/a through <= 2.0.3.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This defect is an improper neutralization of input during web page generation that allows an attacker to inject malicious script code into the output of a WordPress site running the mrsaucier GoogleMapper plugin. The flaw enables reflected XSS, meaning an attacker can craft a URL containing malicious payloads that will be executed in the victim’s browser when they click the link or otherwise load the page. The associated weakness is CWE‑79, which indicates that the input was not properly sanitized or encoded before being included in the rendered page. The potential consequences are session hijacking, credential theft, phishing, and malicious content injection, all of which affect the confidentiality, integrity, and availability of the site and its users.

Affected Systems

All installations of the GoogleMapper WordPress plugin version 2.0.3 and older. The plugin, distributed by mrsaucier, is used to embed Google Maps into WordPress posts and pages. Any site that has one of these versions is susceptible to the vulnerability, regardless of the server environment or WordPress version.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.1, indicating high severity. The EPSS score is below 1%, suggesting the likelihood of exploitation is low at present. It is not listed in the CISA KEV catalog. The exploit path is straightforward: an attacker merely needs to embed a malicious script into a URL parameter or otherwise influence the input that the plugin reflects back to the browser. Because the flaw is a reflected XSS, it does not require authentication or server-side compromise, and any user who visits the crafted URL is at risk.

Generated by OpenCVE AI on May 1, 2026 at 14:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the GoogleMapper plugin to a version newer than 2.0.3.
  • If an immediate upgrade is not possible, sanitize all user‑supplied data that the plugin outputs by applying context‑appropriate escaping functions before rendering the content back to the browser.
  • Monitor the site for unexpected script execution or unusual user activity, and consider disabling or removing the plugin if it is no longer required.

Generated by OpenCVE AI on May 1, 2026 at 14:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5750 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound GoogleMapper allows Reflected XSS. This issue affects GoogleMapper: from n/a through 2.0.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound GoogleMapper allows Reflected XSS. This issue affects GoogleMapper: from n/a through 2.0.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mrsaucier GoogleMapper googlemapper-2 allows Reflected XSS.This issue affects GoogleMapper: from n/a through <= 2.0.3.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 05 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound GoogleMapper allows Reflected XSS. This issue affects GoogleMapper: from n/a through 2.0.3.
Title WordPress GoogleMapper plugin <= 2.0.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:11.777Z

Reserved: 2025-01-16T11:25:42.451Z

Link: CVE-2025-23518

cve-icon Vulnrichment

Updated: 2025-03-05T17:09:57.544Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:39.347

Modified: 2026-04-23T15:23:56.120

Link: CVE-2025-23518

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T15:00:13Z

Weaknesses