Impact
The vulnerability is an improper neutralization of input that results in a reflected cross‑site scripting flaw. When a user requests a specially crafted URL or form submission, the input is incorporated into the generated web page without proper sanitization, causing malicious scripts to run in the victim’s browser. This flaw can allow the execution of arbitrary JavaScript in the context of the website.
Affected Systems
CreativeMindsSolutions supplies the WordPress CM Map Locations plugin. Versions from the initial release up to and including 2.0.8 are susceptible to the reflected XSS vulnerability, meaning any WordPress site that has an affected version installed is at risk.
Risk and Exploitability
The CVSS score of 7.1 signals a moderate‑to‑high impact vulnerability. The EPSS score is less than 1%, indicating a very low but not zero probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to provide a crafted link or input that a user clicks or submits, resulting in the browser executing malicious code.
OpenCVE Enrichment
EUVD