VDB

CVE-2021-25011

CVE-2021-25011 PUBLISHED CVSS 5.699999809265137 MEDIUM

The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's settings.

EPSS 0.43% · 36.5th percentile

Risk Scores

CVSS 3.1
5.699999809265137
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
EPSS Score
0.43%
36.5th percentile

Affected Products

VendorProductVersions
wpgooglemapwp_google_map0
UnknownMaps Plugin using Google Maps for WordPress – WP Google Map1.8.1

Timeline

  • Feb 28, 2022 CVE Published
  • Mar 1, 2022 EPSS Score
  • Apr 22, 2022 EPSS Score
  • Jun 13, 2022 EPSS Score
  • Aug 5, 2022 EPSS Score
  • Sep 26, 2022 EPSS Score
  • Nov 17, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
  • Mar 1, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 23, 2023 EPSS Score
  • Jun 14, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›