This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on the 'place_id' attribute. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-02-05T21:21:56.066Z

Updated: 2024-06-04T17:17:21.520Z

Reserved: 2023-12-16T01:01:04.366Z


Link: CVE-2023-6884

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-02-05T22:15:57.057

Modified: 2024-02-09T17:00:31.857


Link: CVE-2023-6884

JSON object: View

cve-icon Redhat Information

No data.

CWE