Impact
The OSM Map Widget for Elementor plugin is vulnerable to a CWE‑79 stored cross‑site scripting flaw due to insufficient sanitization and escaping of the Map Block URL field. The flaw allows authenticated contributors or higher to inject malicious scripts that execute in the browsers of any visitor who loads a page containing the compromised widget, leading to credential theft, defacement, or session hijacking within the site.
Affected Systems
The vulnerability affects the WordPress plugin OSM Map Widget for Elementor by garbowza, specifically all releases up to and including version 1.3.0. Sites that have installed or upgraded to these versions may have exposed map widgets that accept unsanitized URLs.
Risk and Exploitability
The CVSS score of 6.4 indicates a high severity level, while the EPSS score is below 1%, suggesting a low probability of exploitation at present. The flaw is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with contributor or higher privileges who can edit the map widget. Once successful, the impact is limited to users who view the compromised page but can be severe due to the potential for scripting attacks.
OpenCVE Enrichment
EUVD