CVE-2021-25081

All FrameworksWordPressCWE-352CVE-2021-25081

CVE-2021-25081

State: PUBLISHED · Published: 2022-02-28 · Updated: 2024-08-03 · Assigner: WPScan
Description
The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts and update the plugin's settings via a CSRF attack
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2021/25xxx/CVE-2021-25081.json