CVE-2025-23665
Published: 16 January 2025
Description
Cross-Site Request Forgery (CSRF) vulnerability in Ravi Kumar Vanukuru RSV GMaps rsv-google-maps allows Stored XSS.This issue affects RSV GMaps: from n/a through <= 1.5.
Security Summary
CVE-2025-23665 is a Cross-Site Request Forgery (CSRF) vulnerability, classified under CWE-352, in the RSV GMaps (rsv-google-maps) WordPress plugin developed by Ravi Kumar Vanukuru. The flaw enables Stored XSS and affects all versions from n/a through 1.5 inclusive. It carries a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L).
Attackers can exploit this vulnerability over the network without requiring privileges, though it demands user interaction. By crafting a malicious webpage or resource, an unauthenticated remote attacker can trick an authenticated user into submitting a CSRF request that stores an XSS payload in the plugin, leading to execution in the context of other users viewing the affected content and achieving low-level impacts on confidentiality, integrity, and availability with a changed scope.
The Patchstack advisory provides further details on this WordPress plugin vulnerability, including assessment and recommended actions for mitigation.
Details
- CWE(s)