CVE-2023-44234 MEDIUM

CVE-2023-44234: WordPress WP GPX Maps plugin <= 1.7.08 - Broken Access Control vulnerability

Vendor Bastianon Massimo
Product WP GPX Map
Weakness CWE-862 · Missing authorization
Published June 12, 2024
Last update April 28, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Missing Authorization vulnerability in Bastianon Massimo WP GPX Map.This issue affects WP GPX Map: from n/a through 1.7.08.

Explanation of Vulnerability in Simple Terms

02Summary

WP GPX Map versions 1.7.08 and earlier lack proper authorization checks, allowing authenticated users to modify map data they should not have access to. An attacker with a low-privilege account can alter GPX map content without proper permission validation. The vulnerability affects the plugin's core functionality and requires a valid WordPress login to exploit.

What an attacker can do

03Attacker Capabilities

Modify GPX map data belonging to other users or restricted maps.

Potential impact on your site

04Site Impact

Unauthorized users can alter or corrupt map content, potentially affecting site functionality and user trust.

Conditions required to exploit

05Prerequisites

Attacker must have a valid WordPress user account with at least subscriber-level access.

Key dates

06Disclosure timeline

June 12, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE