Metrics
Affected Vendors & Products
Thu, 13 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 12 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wpgmaps Wpgmaps wp Go Maps |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wpgmaps Wpgmaps wp Go Maps |
Tue, 11 Nov 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJAX action, allowing unauthenticated users to store XSS payloads which are later retrieved from another AJAX call and output unescaped. | |
| Title | WP Google Maps < 9.0.48 - Unauthenticated Stored XSS | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-11-13T18:03:20.350Z
Reserved: 2025-10-04T20:19:25.432Z
Link: CVE-2025-11307
Updated: 2025-11-12T21:26:40.804Z
Status : Awaiting Analysis
Published: 2025-11-11T06:15:34.890
Modified: 2025-11-13T18:15:48.930
Link: CVE-2025-11307
No data.