Impact
The CBX Map for Google Map & OpenStreetMap WordPress plugin allows an authenticated attacker with Contributor or higher privileges to inject arbitrary JavaScript into the plugin’s popup heading and location address fields. These inputs are stored without proper sanitization or escaping, so the malicious script runs whenever any user opens a page that displays the inserted map content. Because the code executes in the victim’s browser, the attacker can hijack sessions, steal credentials, deface sites, or perform further attacks on the user’s behalf.
Affected Systems
The vulnerability affects all releases of the CBX Map for Google Map & OpenStreetMap plugin shipped with WordPress up to and including version 2.0.1. The plugin is distributed by vendor manchumahara and is installed on WordPress sites that have not yet applied the latest update.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score of less than 1% suggests low likelihood of widespread exploitation at present. The flaw is not listed in the CISA KEV catalog. An attacker must be authenticated with at least Contributor role to use the vulnerable add‑map interface, after which the malicious script is stored and served to any site visitor. The attack vector is therefore limited to sites where such roles exist and the plugin is enabled.
OpenCVE Enrichment
EUVD