Executive brief
Google Maps CP is a WordPress plugin used to integrate and display maps on websites. A security flaw allows unauthenticated attackers to inject malicious scripts into the site, which could lead to unauthorized redirects, the display of fraudulent advertisements, or the theft of visitor session information. This occurs when a site visitor or administrator interacts with a specially crafted link or page created by the attacker.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in the Google Maps CP plugin for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted page, leading to the execution of arbitrary JavaScript in the context of the victim's browser session. This can result in session hijacking, unauthorized actions on behalf of the user, or website defacement. The vulnerability is fixed in version 1.2.6.
Affected products
- Codepeople Google Maps CP <= 1.2.5
Timeline
- 2026-06-24: other: Reported by researcher dutafi
- 2026-06-30: advisory: Patchstack advisory published
- 2026-07-02: disclosed: NVD publication date