CVE-2024-5994
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Summary
CVE-2024-5994 is a Stored Cross-Site Scripting vulnerability in the WP Go Maps plugin for WordPress. This issue, affecting versions up to and including 9.0.38, allows authenticated attackers with contributor-level permissions and above to inject arbitrary web scripts into pages. These scripts will execute whenever a user accesses an injected page. The vulnerability can be exploited by attackers who have been granted permissions by administrators. A caution has been added in version 9.0.39 to raise awareness about the potential for abuse with lower-level user permissions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.