CVE Database /
CVE-2021-36870
CVE · Medium
CVE-2021-36870 — WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 8.1.13
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-36870
|
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 8.1.13 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.5
|
< 8.1.13
|
8.1.13 |
2021-06-15 |
—
|
CVE-2021-36870
WP Go Maps versions 8.1.12 and earlier contain multiple authenticated persistent cross-site scripting vulnerabilities affecting several parameters including dataset_name, wpgmza_gdpr_retention_purpose, wpgmza_gdpr_company_name, name, polyname, and address. An authenticated attacker could exploit these flaws to inject malicious scripts that would be stored and executed in the browsers of other users. The vulnerability was discovered by Vlad Visse of the Patchstack Red Team and was resolved in version 8.1.13.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings