Impact
This vulnerability is caused by improper neutralization of input during web page generation in the CreativeMindsSolutions CM Map Locations plugin. The flaw manifests as a reflected cross‑site scripting (XSS) issue, allowing a malicious script to be injected into the page that is rendered for the victim’s browser.
Affected Systems
WordPress sites using the CM Map Locations plugin Version 2.1.6 or earlier are affected. This includes all releases from the plugin’s initial release up to and including 2.1.6. Site administrators who have installed any of these versions are at risk.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high‑severity vulnerability, while an EPSS score of <1% signals a very low current probability of exploitation. The issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires only a crafted URL or form input that is processed by the plugin’s web interface, enabling remote attackers to trigger the XSS effect.
OpenCVE Enrichment
EUVD