Impact
This vulnerability allows authenticated users with Contributor level or higher to inject arbitrary JavaScript into the marker field of the Google Map block. The injected code is stored as part of the block’s JSON, then decoded and rendered directly into HTML on any page that displays the map. As a result, any visitor to the affected page can have the malicious code executed in their browser, leading to credential theft, session hijacking, defacement, or other client‑side attacks.
Affected Systems
WordPress plugin Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns, versions up to and including 6.4.5, is affected. The plugin stores the marker title/content values without proper sanitization or escaping, and the frontend script concatenates them into raw HTML. Attackers need to be logged in with Contributor or higher permissions to create or edit the block.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity, with no EPSS score reported and the vulnerability not listed in the CISA KEV catalog. The attack requires authenticated access and the presence of a Google Map block on a published page. Successful exploitation results in client‑side script execution for all page visitors, potentially enabling data theft or further attacks. Given the moderate CVSS, the risk is significant for sites that use the plugin and allow contributor‑level editing of map blocks.
OpenCVE Enrichment