Impact
The Magic Google Maps plugin contains improper neutralization of input during web page generation, allowing a malformed script to be stored. An attacker can insert JavaScript that will execute whenever a user views a page that renders the stored data, potentially stealing cookies or hijacking sessions. This is a classic character‑encoding issue, identified as CWE‑79.
Affected Systems
WordPress sites that have the Magic Google Maps plugin version 1.0.4 or earlier installed are affected. No earlier vulnerability exists in later releases, and only the vendor version distributed by Fengler:Magic Google Maps is known to be impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% shows a very low probability of exploitation at present. The problem is not listed in the CISA KEV catalog. Attackers would need to inject malicious content into fields stored by the plugin; once stored, the script runs under the context of any visitor who loads the affected page. The level of access needed for this injection is not specified in the advisory and is inferred.
OpenCVE Enrichment
EUVD