Логотип exploitDog
bind:CVE-2025-11307
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-11307

Количество 2

Количество 2

nvd логотип

CVE-2025-11307

3 месяца назад

The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJAX action, allowing unauthenticated users to store XSS payloads which are later retrieved from another AJAX call and output unescaped.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-c6hq-4jpf-r2mq

3 месяца назад

The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJAX action, allowing unauthenticated users to store XSS payloads which are later retrieved from another AJAX call and output unescaped.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-11307

The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJAX action, allowing unauthenticated users to store XSS payloads which are later retrieved from another AJAX call and output unescaped.

CVSS3: 8.8
6%
Низкий
3 месяца назад
github логотип
GHSA-c6hq-4jpf-r2mq

The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJAX action, allowing unauthenticated users to store XSS payloads which are later retrieved from another AJAX call and output unescaped.

CVSS3: 6.1
6%
Низкий
3 месяца назад

Уязвимостей на страницу