CVE Database /
CVE-2023-28172
CVE · Medium
CVE-2023-28172 — WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.4.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-28172
|
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.4.3 |
Cross-Site Request Forgery (CSRF) |
Medium
5.4
|
< 4.4.3
|
4.4.3 |
2023-03-13 |
—
|
CVE-2023-28172
The WP Google Map Plugin contains a cross-site request forgery vulnerability affecting versions through 4.4.2, caused by inadequate nonce verification in the delete() methods of three model classes. An attacker could exploit this flaw to delete locations, categories, or maps by crafting a malicious request and deceiving a site administrator into clicking a link. The vulnerability requires no authentication and can result in unauthorized deletion of map-related content.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings