CVE-2025-13958
Beschrijving NL
De YaMaps for WordPress Plugin WordPress-plug-in vóór 0.6.40 valideert en ontsnapt niet aan enkele van zijn shortcode-attributen voordat deze worden uitgevoerd in een pagina/post waar de shortcode is ingesloten, waardoor gebruikers met de inzenderrol en hoger Stored Cross-Site Scripting-aanvallen kunnen uitvoeren.
Origineel (Engels) tonen
The YaMaps for WordPress Plugin WordPress plugin before 0.6.40 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.