What the vulnerability does
01Description
Missing Authorization vulnerability in Bastianon Massimo WP GPX Map.This issue affects WP GPX Map: from n/a through 1.7.08.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Bastianon Massimo WP GPX Map.This issue affects WP GPX Map: from n/a through 1.7.08.
Explanation of Vulnerability in Simple Terms
WP GPX Map versions 1.7.08 and earlier lack proper authorization checks, allowing authenticated users to modify map data they should not have access to. An attacker with a low-privilege account can alter GPX map content without proper permission validation. The vulnerability affects the plugin's core functionality and requires a valid WordPress login to exploit.
What an attacker can do
Modify GPX map data belonging to other users or restricted maps.
Potential impact on your site
Unauthorized users can alter or corrupt map content, potentially affecting site functionality and user trust.
Conditions required to exploit
Attacker must have a valid WordPress user account with at least subscriber-level access.
Key dates
External resources
Related vulnerabilities