CVE-2014-7182

Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to inject arbitrary web script or HTML via the poly_id parameter in an (1) edit_poly, (2) edit_polyline, or (3) edit_marker action in the wp-google-maps-menu page to wp-admin/admin.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:codecabin:wp_go_maps:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 02:16

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/128694/WordPress-WP-Google-Maps-6.0.26-Cross-Site-Scripting.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/128694/WordPress-WP-Google-Maps-6.0.26-Cross-Site-Scripting.html - Exploit, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/archive/1/533699/100/0/threaded - Third Party Advisory, VDB Entry () http://www.securityfocus.com/archive/1/533699/100/0/threaded - Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/70597 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/70597 - Third Party Advisory, VDB Entry
References () https://wordpress.org/plugins/wp-google-maps/changelog - Product, Release Notes () https://wordpress.org/plugins/wp-google-maps/changelog - Product, Release Notes
References () https://www.htbridge.com/advisory/HTB23236 - Exploit () https://www.htbridge.com/advisory/HTB23236 - Exploit

Information

Published : 2014-10-22 14:55

Updated : 2025-04-12 10:46


NVD link : CVE-2014-7182

Mitre link : CVE-2014-7182

CVE.ORG link : CVE-2014-7182


JSON object : View

Products Affected

codecabin

  • wp_go_maps
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')