An unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in the WP Go Maps (formerly WP Google Maps) WordPress plugin, in versions prior to 9.0.48, allows remote attackers with network access to affected WordPress sites to inject malicious JavaScript via an AJAX action that fails to sanitize user input. The injected payload is stored and later returned through another AJAX endpoint without proper escaping, enabling execution in the context of visiting users’ browsers, potentially leading to credential theft, administrative account takeover, and full site compromise.
The IONIX research team validated the impact through successful exploit reproduction, as detailed in this post.
References:

