VDB
CVE-2022-29453
CVE-2022-29453
PUBLISHED
CVSS 5.400000095367432 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in API KEY for Google Maps plugin <= 1.2.1 at WordPress leading to Google Maps API key update.
EPSS 0.43% · 37.0th percentile
Risk Scores
CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
EPSS Score
0.43%
37.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ayecode | api_key_for_google_maps | 0 |
| AyeCode Ltd | API KEY for Google Maps | * |
Timeline
- Jun 15, 2022 CVE Published
- Jun 16, 2022 EPSS Score
- Aug 4, 2022 EPSS Score
- Sep 22, 2022 EPSS Score
- Nov 9, 2022 EPSS Score
- Dec 28, 2022 EPSS Score
- Feb 14, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 9, 2023 EPSS Score
- Aug 26, 2023 EPSS Score
- Oct 14, 2023 EPSS Score
References
- https://wordpress.org/plugins/api-key-for-google-maps/#developers url
- https://patchstack.com/database/vulnerability/api-key-for-google-maps/wordpress-api-key-for-google-maps-plugin-1-2-1-csrf-vulnerability-leading-to-google-maps-api-key-update url
- https://nvd.nist.gov/vuln/detail/CVE-2022-29453 advisory