Show filters
43 Total Results
Displaying 31-40 of 43
Sort by:
Attacker Value
Unknown
CVE-2023-1913
Disclosure Date: April 06, 2023 (last updated October 08, 2023)
The Maps Widget for Google Maps for WordPress is vulnerable to Stored Cross-Site Scripting via widget settings in versions up to, and including, 4.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
0
Attacker Value
Unknown
CVE-2023-23864
Disclosure Date: March 23, 2023 (last updated November 08, 2023)
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Michael Aronoff Very Simple Google Maps plugin <= 2.8.4 versions.
0
Attacker Value
Unknown
CVE-2023-0037
Disclosure Date: March 13, 2023 (last updated October 08, 2023)
The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
0
Attacker Value
Unknown
CVE-2022-4758
Disclosure Date: January 23, 2023 (last updated October 08, 2023)
The 10WebMapBuilder WordPress plugin before 1.0.72 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
0
Attacker Value
Unknown
CVE-2022-2424
Disclosure Date: August 08, 2022 (last updated October 08, 2023)
The Google Maps Anywhere WordPress plugin through 1.2.6.3 does not sanitise and escape any of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2022-1829
Disclosure Date: June 20, 2022 (last updated October 07, 2023)
The Inline Google Maps WordPress plugin through 5.11 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping
0
Attacker Value
Unknown
CVE-2022-29453
Disclosure Date: June 08, 2022 (last updated October 07, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in API KEY for Google Maps plugin <= 1.2.1 at WordPress leading to Google Maps API key update.
0
Attacker Value
Unknown
CVE-2021-46780
Disclosure Date: April 25, 2022 (last updated October 07, 2023)
The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2021-39346
Disclosure Date: November 01, 2021 (last updated February 23, 2025)
The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/modules/marker_groups/views/tpl/mgrEditMarkerGroup.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.9.33. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.
0
Attacker Value
Unknown
CVE-2014-7238
Disclosure Date: January 23, 2020 (last updated February 21, 2025)
The WordPress plugin Contact Form Integrated With Google Maps 1.0-2.4 has Stored XSS
0