Executive brief
The CodePeople Post Map for Google Maps plugin for WordPress, which allows users to display maps on their posts, contains a security flaw. This vulnerability allows users with basic contributor-level access to inject malicious scripts into website pages. When other visitors or administrators view these pages, the scripts can execute, potentially leading to unauthorized actions or data theft.
Technical details
The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'cpm_point' post meta field. An authenticated attacker with at least Contributor-level permissions can exploit this by injecting malicious JavaScript into the post metadata. Because the plugin fails to properly sanitize this data before storage or escape it during rendering, the script will execute in the browser of any user who views the affected post. This vulnerability is present in all versions up to and including 1.2.6. A patch has been released in subsequent updates.
Affected products
- CodePeople CodePeople Post Map for Google Maps up to, and including, 1.2.6
Timeline
- 2026-06-27: disclosed
- 2026-06-27: advisory
References
- https://plugins.trac.wordpress.org/browser/codepeople-post-map/tags/1.2.6/include/functions.php
- https://plugins.trac.wordpress.org/browser/codepeople-post-map/tags/1.2.6/include/functions.php
- https://plugins.trac.wordpress.org/browser/codepeople-post-map/tags/1.2.6/include/functions.php
- https://plugins.trac.wordpress.org/browser/codepeople-post-map/tags/1.2.6/include/functions.php
- https://plugins.trac.wordpress.org/browser/codepeople-post-map/tags/1.2.6/include/functions.php
- https://plugins.trac.wordpress.org/browser/codepeople-post-map/tags/1.2.6/include/functions.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3586404%40codepeople-post-map&new=3586404%40codepeople-post-map&sfp_email=&sfph_mail=