Impact
A Cross‑Site Request Forgery flaw in the Simple Maps WordPress plugin allows an attacker to inject a persistent script into the plugin’s configuration, leading to stored XSS when users view a map. The stored script can execute in the context of any authenticated user, potentially exposing session cookies, defacing content, or hijacking accounts. The likely attack vector involves persuading a logged‑in administrator to visit a crafted URL that triggers the CSRF action to store malicious data, though this inference is based on the type of vulnerability described.
Affected Systems
The vulnerability affects the Simple Maps interactive‑maps plugin for WordPress, version 0.98 and earlier. Anyone running this plugin on a WordPress site without upgrading to a fixed release is susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high impact, while the EPSS score of less than 1% suggests a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, stored XSS can be executed in the browsers of legitimate users, making the risk non‑negligible. Attackers who can coerce an administrator into visiting a crafted URL may exploit the CSRF mechanism to inject malicious JavaScript, even though no public exploit has been documented.
OpenCVE Enrichment
EUVD