Impact
The vulnerability is an improper neutralization of input during web page generation, allowing attackers to inject malicious scripts through reflected XSS. This flaw falls under CWE‑79 and enables attackers to run code in the browser of any user who visits a crafted URL, potentially compromising session data, defacing content, or redirecting users.
Affected Systems
The affected product is the RealMag777 GMap Targeting WordPress plugin with versions up to and including 1.1.7. WordPress sites installing these plugin versions are at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation. It is not listed in the CISA KEV catalog. Attackers can exploit the flaw by inserting malicious payloads into URLs processed by the plugin, which are then reflected back to the victim without proper sanitization.
OpenCVE Enrichment