What the vulnerability does
01Description
Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensitive Data. This issue affects WP Maps: from n/a through 4.9.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensitive Data. This issue affects WP Maps: from n/a through 4.9.6.
Explanation of Vulnerability in Simple Terms
WP Maps versions up to 4.9.6 expose sensitive information in outbound data sent by the application. An authenticated user with low privileges can trigger the exposure of confidential details through normal use of the plugin. The vulnerability does not allow modification or deletion of data, but information disclosure poses a risk to site security and user privacy.
What an attacker can do
Read sensitive information included in data the plugin sends out.
Potential impact on your site
User data or site configuration details may be exposed to authenticated attackers with basic access.
Conditions required to exploit
Attacker must have a low-privilege account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities