MapFig Studio WordPress Plugin Cross-Site Scripting Vulnerability via Cross-Site Request Forgery

Vulnerability

A stored cross-site scripting vulnerability has been identified in the MapFig Studio WordPress plugin, affecting versions through 0.2.1. The issue arises from the plugin's lack of proper cross-site request forgery (CSRF) checks in certain areas, combined with inadequate data sanitization and escaping. This vulnerability could enable attackers to exploit CSRF to inject malicious scripts that would be executed when a logged-in admin user interacts with the affected content.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the content.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.