PT-2025-14854 · WordPress · Mapsvg Wordpress Plugin

Bob Matyas

·

Published

2025-04-04

·

Updated

2025-04-04

·

CVE-2025-2279

CVSS v3.1

5.9

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Maps WordPress plugin versions 1.0.0 through 1.0.6
Description The issue concerns the Maps WordPress plugin, which does not properly validate and escape some of its shortcode attributes before outputting them in a page or post. This could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Recommendations For Maps WordPress plugin versions 1.0.0 through 1.0.6, update to a version later than 1.0.6 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-2279

Affected Products

Mapsvg Wordpress Plugin