Impact
An unauthenticated Cross Site Scripting vulnerability allows an attacker to inject malicious scripts into the Open User Map plugin’s output. This flaw, classified as CWE‑79, can be exploited by an adversary who visits a compromised page, enabling the execution of arbitrary JavaScript in the victim’s browser, potentially leading to session hijacking, defacement, or theft of sensitive data.
Affected Systems
The vulnerability affects the WordPress Open User Map plugin from 100plugins, versions up to and including 1.4.50. Sites that have installed these versions are susceptible.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating a medium‑to‑high severity level. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is unauthenticated, an attacker does not need privileged access to exploit it, and the absence of an EPSS value suggests that exploitation probability may vary but cannot be confirmed as low or high. The lack of a KEV listing means there is limited evidence of active exploitation in the wild, but the medium‑high severity warrants prompt attention.
OpenCVE Enrichment