Impact
Unauthenticated Cross Site Scripting is present in the WordPress Google Maps CP plugin for versions 1.2.5 and earlier. The CWE‑79 flaw permits an attacker to inject arbitrary JavaScript that executes in a visitor’s browser when they view any page that displays the vulnerable plugin, potentially compromising the integrity of page content and enabling theft of session data or other sensitive information.
Affected Systems
The Codepeople Google Maps CP WordPress plugin, all installations running version 1.2.5 or older, are affected. Sites that use the plugin to embed Google Maps within WordPress posts or pages can be exploited.
Risk and Exploitability
The CVSS score of 7.1 signals high severity. The EPSS score of <1% indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The flaw is unauthenticated; any visitor to a page containing the plugin can trigger the XSS, requiring no privileges or credentials beyond access to the target site.
OpenCVE Enrichment