WP Google Map <= 1.8.0 - Subscriber+ Arbitrary Post Deletion and Plugin Settings Update
2021-12-08 00:00
Krzysztof ZającStrategic Overview
StatusPatched in 1.8.1
Affected PluginMaps Plugin using Google Maps for WordPress – WP Google Map
Affected Version
<= 1.8.0CVSS5.7Medium
CVE
CVE-2021-25011Vulnerability Overview
The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's settings.
Technical Analysis
REMEDIATION: Update to version 1.8.1, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C