Impact
Improper neutralization of input during web page generation in MapSteps UG Ultimate Dashboard Pro creates a DOM-based cross-site scripting flaw. The plug-in accepts user data and renders it without adequate sanitization, allowing an attacker to insert arbitrary JavaScript into the page when a user visits a crafted URL. This can result in session hijacking, defacement, or redirecting users to malicious sites. The vulnerability is a type of input validation failure classified as CWE-79.
Affected Systems
The affected product is MapSteps UG Ultimate Dashboard Pro plugin for WordPress, versions up to and including 3.11.2. Any WordPress installation that has this plugin installed and not upgraded to a newer release is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate-to-high severity. The EPSS score of < 1% indicates a very low but non-zero probability of exploitation, although the flaw is unauthenticated, meaning that an attacker only needs to craft a malicious payload and deliver it through the plugin’s input vectors. The lack of a KEV listing suggests that while there may be no confirmed public exploits, the exposure remains significant, especially for high-traffic sites or those using the plugin’s public contact forms or dashboards.
OpenCVE Enrichment