Impact
Unauthenticated Cross Site Scripting (XSS) exists in WordPress Interactive Geo Maps plugin versions up to 1.6.30. The flaw allows an attacker to embed malicious JavaScript into responses served to users. If an affected user visits a crafted URL, the script runs in their browser, potentially stealing session cookies, defacing content, or redirecting to malicious sites. The weakness is a classic input validation failure, categorized as CWE‑79.
Affected Systems
The vulnerability affects the Interactive Geo Maps plugin developed by MapGeo, used on WordPress sites. Versions 1.6.30 and earlier are impacted; all more recent releases contain the fix. Administrators should verify the installed plugin version and update accordingly.
Risk and Exploitability
The CVSS score of 7.1 indicates a high likelihood of successful exploitation in a typical environment. No EPSS value is available, but the lack of EPSS data does not diminish the potential risk. The vulnerability is not listed in the CISA KEV catalog. The flaw is unauthenticated and can be abused by any user who can shape URLs or input fields, meaning any HTTP request to a vulnerable site could trigger the reflected script. Attackers may gain client‑side compromise and further actions such as credential theft or site defacement.
OpenCVE Enrichment