Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-25011
HistoryFeb 28, 2022 - 9:15 a.m.

Cross site request forgery (csrf)

2022-02-2809:15:00
PRIOn knowledge base
www.prio-n.com
1

5.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.4%

The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin’s settings.

CPENameOperatorVersion
wp_google_maplt1.8.1

5.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.4%

Related for PRION:CVE-2021-25011