CSRF Vulnerability in Easy Google Maps
CVE-2024-31269
8.8HIGH
Summary
The Supsystic Easy Google Maps plugin exhibits a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to perform unwanted actions on behalf of an authenticated user. This vulnerability affects versions up to and including 1.11.11, making it crucial for users to update to the latest version in order to mitigate potential exploits. Attackers can leverage this vulnerability to manipulate map functionalities or alter settings without direct user interaction, posing significant security risks to affected WordPress installations.
Affected Version(s)
Easy Google Maps <= 1.11.11
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Steven Julian (Patchstack Alliance)