PublicCVE

CVE-2022-0208

UNRATEDCross-site scripting
Public PoC

Description

The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting it back in the "Bad mapid" error message, leading to a Reflected Cross-Site Scripting

Affected products

Exploits & proofs of concept