WordPress Add Multiple Marker Plugin <= 1.2 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2022-45080

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 April 2023

What is CVE-2022-45080?

The KrishaWeb Add Multiple Marker plugin for WordPress versions 1.2 and below is susceptible to a Cross-Site Request Forgery (CSRF) attack. This vulnerability allows attackers to trick users into executing unwanted actions on the website, potentially leading to unauthorized access or modification of data without the user's consent. It is essential for users of this plugin to apply security updates and implement measures to mitigate CSRF risks to safeguard their websites.

Affected Version(s)

Add Multiple Marker <= 1.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ptsfence (Patchstack Alliance)
.