WP Google Map <= 1.8.0 - Missing Authorization
2021-12-08 12:44
Nguyen Van KhanhStrategic Overview
StatusPatched in 1.8.1
Affected PluginMaps Plugin using Google Maps for WordPress – WP Google Map
Affected Version
<= 1.8.0CVSS5.4Medium
CVE
CVE-2021-45729Vulnerability Overview
The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authenticated low-role users to create, edit, and delete maps.
Technical Analysis
REMEDIATION: Update to version 1.8.1, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C