Impact
Unauthenticated Cross Site Scripting (XSS) exists in WP Google Maps Pro plugin versions 10.1.02 and earlier, which can allow an attacker to inject arbitrary JavaScript into any page that embeds the plugin. If exploited, the attacker could deface the site, steal session cookies, hijack user sessions, or deliver malware to visitors. The weakness is a classic input validation flaw (CWE‑79).
Affected Systems
The vulnerability affects WordPress sites that install the CodeCabin.io WP Google Maps Pro plugin with any version up to and including 10.1.02. No information is available about specific configuration or deployment scenarios that may mitigate or amplify the risk.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Because authentication is not required, any client visiting a vulnerable page could trigger the payload, making the attack vector public and straightforward once the site is exposed to the internet.
OpenCVE Enrichment