VDB
CVE-2021-25081
CVE-2021-25081
PUBLISHED
CVSS 6.5 MEDIUM
The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts and update the plugin's settings via a CSRF attack
EPSS 0.58% · 46.1th percentile
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS Score
0.58%
46.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Unknown | Maps Plugin using Google Maps for WordPress – WP Google Map | 1.8.4 |
| wpgooglemap | wp_google_map | 0 |
Timeline
- Feb 28, 2022 CVE Published
- Mar 1, 2022 EPSS Score
- Apr 22, 2022 EPSS Score
- Jun 13, 2022 EPSS Score
- Aug 5, 2022 EPSS Score
- Sep 27, 2022 EPSS Score
- Nov 18, 2022 EPSS Score
- Jan 9, 2023 EPSS Score
- Mar 2, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 23, 2023 EPSS Score
- Jun 14, 2023 EPSS Score