Multiple cross-site scripting (XSS) vulnerabilities in the WP GuestMap plugin 1.8 and previous versions for WordPress allow remote malicious users to inject arbitrary web script or HTML via the (1) zl, (2) mt, or (3) dc parameter to guest-locator.php; the (4) zl, (5) mt, (6) activate, or (7) dc parameter to online-tracker.php; the (8) zl, (9) mt, or (10) dc parameter to stats-map.php; or the (11) zl, (12) mt, (13) activate, or (14) dc parameter to weather-map.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
wp guestmap project wp guestmap project |