Vulnerability Description
In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Codecabin | Wp Go Maps | < 7.11.18 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/159640/WordPress-Rest-Google-Maps-SQL-InjecExploitThird Party AdvisoryVDB Entry
- http://www.rapid7.com/db/modules/auxiliary/admin/http/wp_google_maps_sqliExploitThird Party Advisory
- https://plugins.trac.wordpress.org/changeset?old_path=%2Fwp-google-maps&old=2061PatchThird Party Advisory
- https://wordpress.org/plugins/wp-google-maps/#developersThird Party Advisory
- http://packetstormsecurity.com/files/159640/WordPress-Rest-Google-Maps-SQL-InjecExploitThird Party AdvisoryVDB Entry
- http://www.rapid7.com/db/modules/auxiliary/admin/http/wp_google_maps_sqliExploitThird Party Advisory
- https://plugins.trac.wordpress.org/changeset?old_path=%2Fwp-google-maps&old=2061PatchThird Party Advisory
- https://wordpress.org/plugins/wp-google-maps/#developersThird Party Advisory
FAQ
What is CVE-2019-10692?
CVE-2019-10692 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement.
How severe is CVE-2019-10692?
CVE-2019-10692 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-10692?
Check the references section above for vendor advisories and patch information. Affected products include: Codecabin Wp Go Maps.