Impact
This vulnerability allows an attacker to store malicious scripts within the WordPress site via the GMAPS for WPBakery Page Builder Free plugin and have them executed when visitors load affected pages. Because the input is not properly neutralized during web page generation, an attacker could inject scripts that exfiltrate user data, hijack sessions, or deface the site. The weakness is classified as CWE‑79: Improper Neutralization of Input During Web Page Generation.
Affected Systems
WordPress installations that use the WWP:GMAPS for WPBakery Page Builder Free plugin at version 1.2 or earlier are affected. The plugin introduces stored XSS payloads that are later rendered in page output.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low exploitation probability at present. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through any input field provided by the plugin that accepts content which is later stored in the database and rendered unescaped. An attacker who can insert content, for example via a page or post edit, can embed JavaScript that ages for all site visitors.
OpenCVE Enrichment
EUVD