Impact
The vulnerability is a Cross‑Site Request Forgery flaw that allows an attacker to persist malicious script within the RSV GMaps plugin for WordPress. When a privileged user submits a crafted request, the plugin accepts the input and stores it in the database, leading to stored cross‑site scripting that executes whenever the data is rendered. The attacker can then hijack sessions, deface content, and exfiltrate sensitive data.
Affected Systems
The plugin Ravi Kumar Vanukuru RSV GMaps, used in WordPress sites, is affected across all versions from the earliest release through version 1.5. The vulnerability applies to any installation that has the plugin enabled and an authenticated user with sufficient privileges.
Risk and Exploitability
With a CVSS score of 7.1, the vulnerability carries a moderate to high severity. Because an attacker needs authenticated, privileged credentials to trigger the stored XSS payload, the risk is limited to users who can log in. The EPSS score of less than 1% indicates that the probability of exploitation is low. The flaw is not listed in CISA KEV, so no known active exploitation has been reported. Nonetheless, the combination of a CSRF vector and stored XSS makes the flaw a serious threat for sites that rely on the plugin.
OpenCVE Enrichment
EUVD