Vulnerability Description
The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts and update the plugin's settings via a CSRF attack
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wpgooglemap | Wp Google Map | < 1.8.4 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/changeset/2667376Release NotesThird Party Advisory
- https://wpscan.com/vulnerability/f85cf258-1c2f-444e-91e5-b1fc55880f0eExploitThird Party Advisory
- https://plugins.trac.wordpress.org/changeset/2667376Release NotesThird Party Advisory
- https://wpscan.com/vulnerability/f85cf258-1c2f-444e-91e5-b1fc55880f0eExploitThird Party Advisory
FAQ
What is CVE-2021-25081?
CVE-2021-25081 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts a...
How severe is CVE-2021-25081?
CVE-2021-25081 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-25081?
Check the references section above for vendor advisories and patch information. Affected products include: Wpgooglemap Wp Google Map.