Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation flaw that allows a stored cross‑site scripting (XSS) payload to be injected via the Embed Google Map plugin. An attacker who can supply map configuration data could embed malicious JavaScript that would execute in the browsers of any user who views the affected page, potentially leading to credential theft, session hijacking, or defacement. The weakness is classified as CWE‑79 because the plugin fails to properly sanitize user input before rendering it on the front end.
Affected Systems
Petkivim's Embed Google Map WordPress plugin is affected for all releases up to and including version 3.2. Users running these versions, or any 3.2‑based installation, must consider the plugin unsafe until a fix is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, so no widespread exploitation has been documented. The likely attack vector is through the plugin’s input fields that persist data in the database; an authenticated user with access to the plugin settings could inject malicious code. If such input is rendered without sanitization, any visitor to the site can be impacted.
OpenCVE Enrichment
EUVD