{"api_version":"1","generated_at":"2026-04-24T02:50:50+00:00","cve":"CVE-2021-24383","urls":{"html":"https://cve.report/CVE-2021-24383","api":"https://cve.report/api/cve/CVE-2021-24383.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-24383","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-24383"},"summary":{"title":"CVE-2021-24383","description":"The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue","state":"PUBLIC","assigner":"contact@wpscan.com","published_at":"2021-06-21 20:15:00","updated_at":"2023-05-24 00:49:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/1270588c-53fe-447e-b83c-1b877dc7a954","name":"https://wpscan.com/vulnerability/1270588c-53fe-447e-b83c-1b877dc7a954","refsource":"CONFIRM","tags":[],"title":"WP Google Maps < 8.1.12 - Authenticated Stored Cross-Site Scripting (XSS) Security Vulnerability","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/163261/WordPress-WP-Google-Maps-8.1.11-Cross-Site-Scripting.html","name":"http://packetstormsecurity.com/files/163261/WordPress-WP-Google-Maps-8.1.11-Cross-Site-Scripting.html","refsource":"MISC","tags":[],"title":"WordPress WP Google Maps 8.1.11 Cross Site Scripting ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-24383","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-24383","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Mohammed Adam","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"24383","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"codecabin","cpe5":"wp_google_maps","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"24383","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"codecabin","cpe5":"wp_go_maps","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ID":"CVE-2021-24383","ASSIGNER":"contact@wpscan.com","STATE":"PUBLIC","TITLE":"WP Google Maps < 8.1.12 - Authenticated Stored Cross-Site Scripting (XSS)"},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","generator":"WPScan CVE Generator","affects":{"vendor":{"vendor_data":[{"vendor_name":"WP Google Maps","product":{"product_data":[{"product_name":"WP Google Maps","version":{"version_data":[{"version_affected":"<","version_name":"8.1.12","version_value":"8.1.12"}]}}]}}]}},"description":{"description_data":[{"lang":"eng","value":"The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue"}]},"references":{"reference_data":[{"refsource":"CONFIRM","url":"https://wpscan.com/vulnerability/1270588c-53fe-447e-b83c-1b877dc7a954","name":"https://wpscan.com/vulnerability/1270588c-53fe-447e-b83c-1b877dc7a954"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/163261/WordPress-WP-Google-Maps-8.1.11-Cross-Site-Scripting.html","url":"http://packetstormsecurity.com/files/163261/WordPress-WP-Google-Maps-8.1.11-Cross-Site-Scripting.html"}]},"problemtype":{"problemtype_data":[{"description":[{"value":"CWE-79 Cross-site Scripting (XSS)","lang":"eng"}]}]},"credit":[{"lang":"eng","value":"Mohammed Adam"}],"source":{"discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2021-06-21 20:15:00","lastModifiedDate":"2023-05-24 00:49:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:codecabin:wp_go_maps:*:*:*:*:*:wordpress:*:*","versionEndExcluding":"8.1.12","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"24383","Ordinal":"199145","Title":"CVE-2021-24383","CVE":"CVE-2021-24383","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"24383","Ordinal":"1","NoteData":"The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue","Type":"Description","Title":null},{"CveYear":"2021","CveId":"24383","Ordinal":"2","NoteData":"2021-06-21","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"24383","Ordinal":"3","NoteData":"2021-06-23","Type":"Other","Title":"Modified"}]}}}