CVE Database /
CVE-2022-25600
CVE · High
CVE-2022-25600 — WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.4.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-25600
|
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.4.3 |
Cross-Site Request Forgery (CSRF) |
High
8.8
|
< 4.4.3
|
4.4.3 |
2022-02-22 |
—
|
CVE-2022-25600
The WP Maps plugin before version 4.4.3 lacks cross-site request forgery protections on several administrative functions, including marker category deletion, map deletion, and map duplication. This vulnerability permits attackers to trick authenticated administrators into executing these destructive actions without their knowledge through malicious requests.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings