What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Bas Matthee LSD Google Maps Embedder lsd-google-maps-embedder allows Cross Site Request Forgery.This issue affects LSD Google Maps Embedder: from n/a through <= 1.1.
Explanation of Vulnerability in Simple Terms
02Summary
LSD Google Maps Embedder versions 1.1 and earlier are vulnerable to cross-site request forgery (CSRF). An attacker can craft a malicious webpage that, when visited by a site administrator, performs unwanted actions on the site without their knowledge. The vulnerability requires the admin to visit the attacker's page while logged in. Updating to a version newer than 1.1 is recommended.
What an attacker can do
03Attacker Capabilities
Perform unwanted actions on the site by tricking an admin into visiting a malicious webpage.
Potential impact on your site
04Site Impact
An attacker can modify site settings or content if an admin visits a malicious link while logged in.
Conditions required to exploit
05Prerequisites
Site admin must visit attacker-controlled webpage while logged into WordPress.
Key dates
06Disclosure timeline
January 16, 2025
CVE published
May 12, 2026
Record updated