The MapPress Maps for WordPress plugin before 2.94.9 does not sanitise and escape some parameters when outputing them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.
History

Tue, 29 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Mappresspro
Mappresspro mappress
Weaknesses CWE-79
CPEs cpe:2.3:a:mappresspro:mappress:*:*:*:*:free:wordpress:*:*
Vendors & Products Mappresspro
Mappresspro mappress

Thu, 03 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Apr 2025 14:00:00 +0000

Type Values Removed Values Added
Title MapPress Maps for WordPress < 2.94.9 - Contributor+ Stored XSS

Thu, 03 Apr 2025 06:45:00 +0000

Type Values Removed Values Added
Description The MapPress Maps for WordPress plugin before 2.94.9 does not sanitise and escape some parameters when outputing them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-04-03T06:00:04.999Z

Updated: 2025-04-03T13:50:37.497Z

Reserved: 2025-03-06T14:54:03.388Z

Link: CVE-2025-2055

cve-icon Vulnrichment

Updated: 2025-04-03T13:50:14.558Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-03T06:15:42.727

Modified: 2025-04-29T20:49:45.147

Link: CVE-2025-2055

cve-icon Redhat

No data.