CVE · Medium

CVE-2023-28172 — WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.4.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-28172 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.4.3 Cross-Site Request Forgery (CSRF) Medium 5.4 < 4.4.3 4.4.3 2023-03-13

CVE-2023-28172

The WP Google Map Plugin contains a cross-site request forgery vulnerability affecting versions through 4.4.2, caused by inadequate nonce verification in the delete() methods of three model classes. An attacker could exploit this flaw to delete locations, categories, or maps by crafting a malicious request and deceiving a site administrator into clicking a link. The vulnerability requires no authentication and can result in unauthorized deletion of map-related content.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.