SQL Injection Vulnerability in wp-google-maps Plugin for WordPress
CVE-2019-10692
9.8CRITICAL
Summary
The wp-google-maps plugin prior to version 7.11.18 for WordPress contains an SQL injection vulnerability. Specifically, the issue arises from the inclusion of include/class.rest-api.php, where certain field names are not properly sanitized prior to being used in a SELECT statement. This oversight could allow malicious actors to manipulate SQL queries, potentially leading to unauthorized access to sensitive data or further exploits within the web application.
References
EPSS Score
95% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved