The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
2025-05-01T06:15:34.820
2025-05-07T16:30:24.910
Analyzed
CVSSv3.1: 4.8 (MEDIUM)