Vulnerabilities > CVE-2022-1772 - Unspecified vulnerability in Google Places Reviews Project Google Places Reviews
Attack vector
NETWORK Attack complexity
LOW Privileges required
HIGH Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped payload and taking over their account.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |