The MapPress Maps for WordPress plugin before 2.94.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
History

Wed, 28 May 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Mappresspro
Mappresspro mappress
Weaknesses CWE-79
CPEs cpe:2.3:a:mappresspro:mappress:*:*:*:*:free:wordpress:*:*
Vendors & Products Mappresspro
Mappresspro mappress

Fri, 18 Apr 2025 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


Fri, 18 Apr 2025 06:15:00 +0000

Type Values Removed Values Added
Description The MapPress Maps for WordPress plugin before 2.94.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Title MapPress Maps for WordPress < 2.94.10 - Admin+ Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-04-18T06:00:08.243Z

Updated: 2025-04-18T12:00:29.424Z

Reserved: 2025-03-10T13:37:40.026Z

Link: CVE-2025-2162

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2025-04-18T06:15:43.593

Modified: 2025-05-28T17:43:00.733

Link: CVE-2025-2162

cve-icon Redhat

No data.