MapPress Maps <= 2.54.5 - Remote Code Execution via Improper Capability Checks in AJAX Calls
2020-05-28 00:00
Alert LogicStrategic Overview
StatusPatched in 2.54.6
Affected PluginMapPress – Google Maps, OpenStreetMap & Leaflet
Affected Version
<= 2.54.5CVSS8.8High
CVE
CVE-2020-12675Vulnerability Overview
The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related to creation/retrieval/deletion of PHP template files, leading to Remote Code Execution. NOTE: this issue exists because of an incomplete fix for CVE-2020-12077.
Technical Analysis
REMEDIATION: Update to version 2.54.6, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C