RSS   Vulnerabilities for 'Easy google maps'   RSS

2022-04-25
 
CVE-2021-46780

CWE-79
 

 
The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

 
2021-11-01
 
CVE-2021-39346

CWE-79
 

 
The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/modules/marker_groups/views/tpl/mgrEditMarkerGroup.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.9.33. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

 

 >>> Vendor: Supsystic 10 Products
Contact form
Popup
Newsletter by supsystic
Pricing table by supsystic
Data tables generator
Ultimate maps
Easy google maps
Price table
Social share buttons
Digital publications by supsystic


Copyright 2024, cxsecurity.com

 

Back to Top