WordPress WP Google Map Plugin Plugin <= 4.4.2 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-28172

5.4MEDIUM

What is CVE-2023-28172?

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP MAPS plugin by Flippercode. This affects versions 4.4.2 and earlier, enabling attackers to exploit the security weaknesses by sending unauthorized requests on behalf of users. If successfully manipulated, this flaw could lead to unintended actions being performed without user consent, potentially compromising the integrity and security of the affected WordPress instances. Users of this plugin are urged to implement necessary security measures to mitigate risks.

Affected Version(s)

WordPress Plugin for Google Maps – WP MAPS (formerly WP Google Map Plugin) <= 4.4.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.