Impact
Yuriy Baranov’s YaMaps for WordPress plugin contains an improper neutralization of user input when generating web pages, which allows stored cross‑site scripting. Malicious code that is entered through the plugin’s input fields can be retained and later rendered in the browser, giving an attacker the ability to run arbitrary JavaScript in the context of any user who views the affected page.
Affected Systems
All installations of YaMaps for WordPress version 0.6.40 or earlier are affected. Any WordPress site that includes the plugin in that version range is vulnerable, regardless of other configuration settings.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 indicates a moderate severity. The EPSS score of less than 1% reflects a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to provide input that the plugin accepts and stores; the compromised data is then served to any user who views the page. No additional privileges are required beyond having access to the plugin’s input interface.
OpenCVE Enrichment
EUVD