CVE 6.1 MEDIUM

WP Google Maps < 9.0.48 - Unauthenticated Stored XSS_CVE-2025-11307

6.1 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Description

The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJAX action, allowing unauthenticated users to store XSS payloads which are later retrieved from another AJAX call and output unescaped.

Basic Information

ID CVE-2025-11307
Source WPScan
Published Nov 11, 2025 at 06:00
Modified Nov 12, 2025 at 21:26

Affected Product

Vendor Unknown
Product WP Go Maps (formerly WP Google Maps)
Affected Versions Unknown WP Go Maps (formerly WP Google Maps) 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.