VDB
CVE-2023-5128
CVE-2023-5128
PUBLISHED
CVSS 6.400000095367432 MEDIUM
The TCD Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'map' shortcode in versions up to, and including, 1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
EPSS 0.54% · 44.3th percentile
Risk Scores
CVSS 3.1
6.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
EPSS Score
0.54%
44.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| designplus | TCD Google Maps | *, 0 |
| tcd-theme | tcd_google_maps | 0, 0 |
Timeline
- Nov 22, 2023 CVE Published
- Nov 23, 2023 EPSS Score
- Dec 23, 2023 EPSS Score
- Jan 23, 2024 EPSS Score
- Feb 22, 2024 EPSS Score
- Mar 23, 2024 EPSS Score
- Apr 23, 2024 EPSS Score
- May 23, 2024 EPSS Score
- Jun 22, 2024 EPSS Score
- Aug 22, 2024 EPSS Score
- Sep 21, 2024 EPSS Score
- Oct 5, 2024 Coalition ESS Score
References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/50f6d0aa-059d-48d9-873b-6404f288f002?source=cve url
- https://nvd.nist.gov/vuln/detail/CVE-2023-5128 advisory
- https://plugins.trac.wordpress.org/browser/tcd-google-maps/trunk/design-plus-google-maps.php?rev=2700917#L169 url
- https://plugins.trac.wordpress.org/browser/tcd-google-maps/trunk/design-plus-google-maps.php?rev=2700917#L154 url