Impact
Improper neutralization of input during web page generation in the Google Earth Embed plugin allows a stored XSS payload to be executed in the browsers of visitors who load the compromised content. The flaw can cause arbitrary client‑side code to run when the embedded tours are rendered.
Affected Systems
The Andrew Norcross Google Earth Embed plugin version 1.0 and earlier are affected. Any WordPress site that uses this plugin may be impacted when the stored content is viewed.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. An EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could supply malicious code via the plugin’s administrative interface, which is then served to all site visitors during normal page generation.
OpenCVE Enrichment
EUVD