
Cloud Vulnerability DB
A community-led vulnerabilities database
The CVE-2025-32138 is an XML External Entity (XXE) vulnerability discovered in the Easy Google Maps WordPress plugin affecting versions up to and including 1.11.17. The vulnerability was publicly disclosed on April 4, 2025, and allows XML injection through improper restriction of XML external entity references (NVD, Patchstack).
The vulnerability is classified as CWE-611 (Improper Restriction of XML External Entity Reference). It received a CVSS v3.1 base score of 6.6 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L. The vulnerability requires author-level access or higher privileges to exploit (WPScan, Patchstack).
The XXE vulnerability could potentially allow authenticated attackers to perform XML injection, which may lead to information disclosure, denial of service, and server-side request forgery. The impact is considered medium severity due to the requirement of authenticated access (Patchstack).
Currently, there is no official fix available for this vulnerability. The latest affected version is 1.11.17, and users are advised to implement proper XML parsing controls and restrict access to the affected functionality (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."