Executive brief
MK Google Directions is a WordPress plugin used to calculate and display travel distances using Google Maps data. A security flaw in this plugin allows an attacker with basic contributor-level access to inject malicious scripts into the website. If a site visitor or administrator views the affected content, the script could steal session information, redirect users to malicious sites, or deface the website.
Technical details
The MK Google Directions (google-distance-calculator) plugin for WordPress is vulnerable to DOM-based Cross-Site Scripting (XSS) due to improper neutralization of input during web page generation. The vulnerability exists in versions up to and including 3.1.1. An attacker with 'Contributor' level privileges or higher can inject malicious JavaScript into the DOM, which is then executed in the context of a victim's browser when they interact with the affected page. This is classified as CWE-79. As of the advisory date, no official patch has been released, and users are advised to monitor for updates or seek alternative solutions.
Affected products
- Manoj Kumar MK Google Directions (google-distance-calculator) <= 3.1.1
Timeline
- 2026-01-20: other: Vulnerability reported by researcher Riski Gana Prasetya
- 2026-02-19: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published to NVD