Impact
The vulnerability allows stored cross‑site scripting because user provided data is not properly neutralized when the web page is generated. An attacker can inject malicious script that executes in the browsers of any user who views the affected content, enabling theft of session data, defacement, or other client‑side attacks. The weakness is a classic input validation flaw (CWE‑79).
Affected Systems
WordPress sites using the icopydoc Maps for WP plugin version 1.2.5 or earlier are affected. The issue exists from initial release through 1.2.5, as the plugin stores map data without sanitization.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score of less than 1% shows a very low probability of exploitation. It is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely via an unfiltered input field that stores map information, which is then rendered on visited pages. A successful exploit requires an attacker to supply malicious input and a victim to view the stored content.
OpenCVE Enrichment
EUVD