CVE · Medium

CVE-2021-36870 — WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 8.1.13

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-36870 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 8.1.13 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.5 < 8.1.13 8.1.13 2021-06-15

CVE-2021-36870

WP Go Maps versions 8.1.12 and earlier contain multiple authenticated persistent cross-site scripting vulnerabilities affecting several parameters including dataset_name, wpgmza_gdpr_retention_purpose, wpgmza_gdpr_company_name, name, polyname, and address. An authenticated attacker could exploit these flaws to inject malicious scripts that would be stored and executed in the browsers of other users. The vulnerability was discovered by Vlad Visse of the Patchstack Red Team and was resolved in version 8.1.13.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.