CVE-2021-25081
Description
The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts and update the plugin's settings via a CSRF attack
CWE
- CWE-352 — CWE-352 Cross-Site Request Forgery (CSRF)
Affected
- Unknown / Maps Plugin using Google Maps for WordPress – WP Google Map — v=1.8.4 <1.8.4 [affected]
CVSS
- (none)
References
- https://wpscan.com/vulnerability/f85cf258-1c2f-444e-91e5-b1fc55880f0e x_refsource_MISC
- https://plugins.trac.wordpress.org/changeset/2667376 x_refsource_CONFIRM
Source
cvelistV5-main/cves/2021/25xxx/CVE-2021-25081.json