WordPress WP Google Map Plugin Plugin <= 4.4.2 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-28172
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 12 November 2023
What is CVE-2023-28172?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP MAPS plugin by Flippercode. This affects versions 4.4.2 and earlier, enabling attackers to exploit the security weaknesses by sending unauthorized requests on behalf of users. If successfully manipulated, this flaw could lead to unintended actions being performed without user consent, potentially compromising the integrity and security of the affected WordPress instances. Users of this plugin are urged to implement necessary security measures to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WordPress Plugin for Google Maps β WP MAPS (formerly WP Google Map Plugin) <= 4.4.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved