Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-0420


The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back in the admin dashboard, allowing Contributors and above roles to perform Stored Cross-Site Scripting attacks


Published

2024-02-12T16:15:08.557

Last Modified

2024-11-21T08:46:32.963

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mappresspro mappress_maps_for_wordpress < 2.88.15 Yes

References