ZeroHour

CVE-2021-25011

PoC
CVSS 3.1
5.7 medium
EPSS
<1%p36
Published
()
Modified
Description

The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's settings.

Vendors
wpgooglemap
Products
wp google map
Ecosystems
WordPress
Weakness
CWE-862, CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.