WordPress WP Google Map Plugin Plugin <= 4.4.2 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-28172
8.8HIGH
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 12 November 2023
Summary
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP MAPS plugin by Flippercode. This affects versions 4.4.2 and earlier, enabling attackers to exploit the security weaknesses by sending unauthorized requests on behalf of users. If successfully manipulated, this flaw could lead to unintended actions being performed without user consent, potentially compromising the integrity and security of the affected WordPress instances. Users of this plugin are urged to implement necessary security measures to mitigate risks.
Affected Version(s)
WordPress Plugin for Google Maps – WP MAPS (formerly WP Google Map Plugin) <= 4.4.2
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafie Muhammad (Patchstack)