CVE · High

CVE-2022-25600 — WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.4.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-25600 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.4.3 Cross-Site Request Forgery (CSRF) High 8.8 < 4.4.3 4.4.3 2022-02-22

CVE-2022-25600

The WP Maps plugin before version 4.4.3 lacks cross-site request forgery protections on several administrative functions, including marker category deletion, map deletion, and map duplication. This vulnerability permits attackers to trick authenticated administrators into executing these destructive actions without their knowledge through malicious requests.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.