CVE · Medium

CVE-2024-5994 — WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.39

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-5994 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.39 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 9.0.39 9.0.39 2024-06-13

CVE-2024-5994

A stored cross-site scripting vulnerability has been identified in WP Go Maps plugin, affecting versions up to and including 9.0.38. This flaw allows authorized attackers with contributor or higher permissions to embed malicious scripts that will run when a user visits the affected page. The issue is addressed in version 9.0.39, which includes a warning for administrators about potential misuse of lower-level user permissions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.