Sceawere

Vulnerability Detail

CVE-2026-102395UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Easy Google Maps Unauthenticated XSS

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
supsystic
Product
Easy Google Maps
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-09-30T13:17:17.380Z",
  "pubdate": "2026-09-30T13:17:17.380Z",
  "executiveSummary": "The Easy Google Maps plugin for WordPress, in versions 1.14.6 and below, contains a critical vulnerability involving unauthenticated Cross-Site Scripting (XSS).\nThis vulnerability allows unauthenticated, remote attackers to inject arbitrary malicious scripts into web pages rendered by the plugin.\nThe security flaw stems from the improper sanitization and validation of user-supplied input before reflecting it back to the victim's browser.\nSuccessful exploitation permits the execution of malicious JavaScript in the context of a victim's session, potentially leading to unauthorized actions, session hijacking, or the theft of sensitive data, such as administrative cookies or authentication tokens.\nGiven that the attack does not require authentication, the risk to affected WordPress installations is high, as malicious actors can target users visiting the site without needing prior access or privileges.\nThe flaw impacts all deployments of Easy Google Maps up to version 1.14.6, necessitating immediate remediation efforts to prevent potential compromise.",
  "technicalDetails": "The root cause of the vulnerability is insufficient input sanitization and output encoding within the Easy Google Maps plugin. The affected component fails to adequately validate parameters handled by the plugin, allowing attackers to inject crafted malicious payloads directly into the application's response stream.\nThe vulnerability is categorized as Reflected Cross-Site Scripting (XSS), as the malicious script is not persistently stored on the server but is included in a crafted URL or request parameters that the plugin reflects directly back to the user.\nThe attack flow proceeds as follows: An unauthenticated attacker crafts a malicious request containing a payload designed to execute JavaScript (e.g., using <script> tags or event handlers like 'onload'). This request is sent to a vulnerable endpoint within the Easy Google Maps plugin. Because the plugin processes this input and renders it back in the HTML response without proper sanitization, the browser receives and executes the attacker's script.\nSince the attack executes in the browser of the victim (which could include an administrative user), the impact is significant. The executed JavaScript can perform actions on behalf of the victim, such as modifying plugin configurations, creating new administrator accounts, exfiltrating data, or redirecting the user to malicious sites.\nThe exposure is network-based, meaning any user reachable by the web server can trigger the injection. No specific authentication or elevated privileges are required to initiate the attack, making it trivial for an automated scanner or a motivated attacker to exploit.\nThe payload behavior depends on the attacker's objectives; however, common exploitation involves bypassing same-origin policy (SOP) restrictions to gain access to sensitive session information or performing arbitrary actions via HTTP requests that the plugin exposes. The failure to apply context-aware output encoding (such as escaping characters like '<', '>', '&', '\"', and \"'\") during the rendering process is the primary technical failure allowing this injection."
}
CVE-2026-102395: Easy Google Maps Unauthenticated XSS (HIGH Severity, CVSS: 7.1) | Sceawere