Vulnerabilities > Wpgooglemap

DATE CVE VULNERABILITY TITLE RISK
2022-02-28 CVE-2021-25011 Cross-Site Request Forgery (CSRF) vulnerability in Wpgooglemap WP Google MAP
The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's settings.
network
low complexity
wpgooglemap CWE-352
5.7
2022-02-28 CVE-2021-25081 Cross-Site Request Forgery (CSRF) vulnerability in Wpgooglemap WP Google MAP
The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts and update the plugin's settings via a CSRF attack
4.3