VDB

CVE-2023-0037

CVE-2023-0037 PUBLISHED CVSS 9.800000190734863 CRITICAL

The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

EPSS 3.91% · 89.8th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
3.91%
89.8th percentile

Affected Products

VendorProductVersions
Unknown10Web Map Builder for Google Maps0
10webmap_builder_for_google_maps0

Timeline

  • Mar 3, 2023 VulnCheck KEV Exploitation
  • Mar 13, 2023 CVE Published
  • Mar 14, 2023 EPSS Score
  • May 31, 2023 EPSS Score
  • Jul 9, 2023 EPSS Score
  • Sep 24, 2023 EPSS Score
  • Nov 2, 2023 EPSS Score
  • Jan 19, 2024 EPSS Score
  • Apr 6, 2024 EPSS Score
  • May 14, 2024 EPSS Score
  • Jul 31, 2024 EPSS Score
  • Oct 17, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›