What the vulnerability does
01Description
The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authenticated low-role users to create, edit, and delete maps.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authenticated low-role users to create, edit, and delete maps.
Explanation of Vulnerability in Simple Terms
The WP Google Map plugin version 1.8.0 and earlier contains a privilege management flaw that allows authenticated users with low privileges to modify site data. An attacker with a basic user account can alter or delete map-related content without proper authorization checks. This affects the integrity and availability of map functionality on affected WordPress sites.
What an attacker can do
Modify or delete map data and settings with a low-privilege user account.
Potential impact on your site
Map content and settings can be altered or deleted by unauthorized users, disrupting site functionality.
Conditions required to exploit
Attacker must have a valid WordPress user account with low privileges (e.g., Subscriber or Contributor role).
Key dates
External resources
Related vulnerabilities