Impact
The WordPress wp_amaps plugin version 1.7 and earlier contains an improper neutralization of user input which allows attackers to inject malicious scripts into the rendered page. This constitutes a stored cross-site scripting flaw (CWE-79) that can compromise the confidentiality, integrity, and availability of browsers visiting affected sites by enabling session hijacking, phishing, or execution of arbitrary JavaScript in the victim's context.
Affected Systems
The vulnerability affects the WordPress wp_amaps plugin developed by rccoder. All releases from the earliest available up to and including version 1.7 are impacted. Users who have installed any of these versions are at risk.
Risk and Exploitability
The CVSS score of 6.5 categorizes the flaw as moderate, while the EPSS score of less than 1% indicates a very low exploitation probability at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is the plugin's input handling—an attacker can supply malicious input that is then reflected and persisted, eventually executing within a victim's browser when the page is rendered.
OpenCVE Enrichment
EUVD