Unauthorized Data Modification in WordPress Plugin by Vendor
CVE-2025-11999
5.3MEDIUM
What is CVE-2025-11999?
The Add Multiple Marker plugin for WordPress has a security flaw that allows unauthorized users to modify data due to inadequate capability checks on critical functions. Specifically, the functions addmultiplemarker_reset_map() and amm_save_map_api() lack necessary verifications, enabling unauthenticated attackers to alter the map API and reset maps, posing a risk to website integrity.
Affected Version(s)
Add Multiple Marker * <= 1.2