6.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Description
The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple fields in versions up to, and including, 1.20.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Basic Information
ID
CVE-2025-9044
Source
Wordfence
Published
Sep 26, 2025 at 03:25
Affected Product
Vendor
mapster
Product
Mapster WP Maps
Version
*
Affected Versions
mapster Mapster WP Maps *
CWE Classification
References
- www.wordfence.com /threat-intel/vulnerabilities/id/b0f2c7f0-ff24-4489-9fb4-8a98ac6dc09a
- plugins.trac.wordpress.org /browser/mapster-wp-maps/tags/1.18.0/admin/includes/acf-map-fields.php
- plugins.trac.wordpress.org /browser/mapster-wp-maps/tags/1.18.0/admin/includes/acf-map-fields.php
- plugins.trac.wordpress.org /browser/mapster-wp-maps/tags/1.18.0/admin/includes/acf-map-fields.php
- plugins.trac.wordpress.org /browser/mapster-wp-maps/tags/1.18.0/admin/includes/acf-map-fields.php
- plugins.trac.wordpress.org /changeset