Cyber Posture

CVE-2025-23665

High

Published: 16 January 2025

Published
16 January 2025
Modified
23 April 2026
KEV Added
Patch
CVSS Score 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
EPSS Score 0.0004 12.2th percentile
Risk Priority 14 60% EPSS · 20% KEV · 20% CVSS

Description

Cross-Site Request Forgery (CSRF) vulnerability in Ravi Kumar Vanukuru RSV GMaps rsv-google-maps allows Stored XSS.This issue affects RSV GMaps: from n/a through <= 1.5.

Security Summary

CVE-2025-23665 is a Cross-Site Request Forgery (CSRF) vulnerability, classified under CWE-352, in the RSV GMaps (rsv-google-maps) WordPress plugin developed by Ravi Kumar Vanukuru. The flaw enables Stored XSS and affects all versions from n/a through 1.5 inclusive. It carries a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L).

Attackers can exploit this vulnerability over the network without requiring privileges, though it demands user interaction. By crafting a malicious webpage or resource, an unauthenticated remote attacker can trick an authenticated user into submitting a CSRF request that stores an XSS payload in the plugin, leading to execution in the context of other users viewing the affected content and achieving low-level impacts on confidentiality, integrity, and availability with a changed scope.

The Patchstack advisory provides further details on this WordPress plugin vulnerability, including assessment and recommended actions for mitigation.

Details

CWE(s)
CWE-352

References