Impact
Unauthenticated Cross Site Scripting (XSS) vulnerability affects WordPress Easy Google Maps plugin versions 1.14.6 and earlier. Attackers can inject arbitrary client‑side script when the vulnerable plugin processes data, enabling them to hijack user sessions, deface web pages, or steal credentials from unsuspecting visitors. The flaw corresponds to CWE-79 and poses a confidentiality, integrity, and availability risk for all users who view maps rendered by the plugin.
Affected Systems
The vulnerability is present in the Easy Google Maps plugin for WordPress, developed by the vendor supsystic. Affected releases are all versions up to and including 1.14.6. The latest patched release is 1.15.1.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity of the flaw. There is no EPSS score available, making it unclear how frequently the exploit is attempted, and the issue is not listed in CISA KEV. The attack does not require authentication, so any user visiting the site may be impacted. Exploitation requires only that the site runs a vulnerable plugin version; no additional privileges are needed. Given the remote nature of XSS, attackers can target any publicly accessible WordPress site using the plugin.
OpenCVE Enrichment