WP Google Map <= 1.8.0 - Missing Authorization

2021-12-08 12:44
Nguyen Van Khanh

Strategic Overview

Vulnerability Overview

The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authenticated low-role users to create, edit, and delete maps.

Technical Analysis

REMEDIATION: Update to version 1.8.1, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C