Impact
This vulnerability is a DOM‑based XSS in the Simple Google Static Map plugin. The plugin fails to sanitize user‑supplied map URLs, enabling an attacker to inject JavaScript that runs in the context of any visitor to a page that includes the map. The attacker could steal session cookies, deface content, or redirect users to fraudulent sites.
Affected Systems
The issue is present in all variants of the plugin released up to and including version 1.0.1, distributed through WordPress. It applies to installations running any WordPress site that has the Simple Google Static Map plugin installed and active, regardless of the theme or other plugins.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1 % shows a low likelihood of automated attacks. The weakness is listed as CWE‑79 and is not currently in the CISA KEV catalog. Exploitation requires a user to view a page containing the maliciously crafted map URL, which is typical of a phishing or social‑engineering attack rather than a network‑level exploit.
OpenCVE Enrichment
EUVD