Impact
Missing authorization in the Advanced Google Maps plugin allows a user to access functions that should be restricted, exposing map data and potentially enabling further exploitation. The flaw is a classic Broken Access Control (CWE-862).
Affected Systems
WordPress sites running flippercode Advanced Google Maps plugin, version 5.8.4 or earlier, including any earlier releases.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The CVE description notes missing authorization checks, which may allow users with inappropriate privileges to invoke restricted actions. The exact attack vector is not specified; it could involve authenticated users exploiting improper access controls or potentially unauthenticated users if endpoints are publicly reachable. This vulnerability is not listed in CISA’s KEV catalog, indicating no widely available exploits have been reported.
OpenCVE Enrichment