CVE-2023-25039 – WordPress Google Maps CP plugin <= 1.0.43 - Missing Authorization Leading To Feedback Submission Vulnerability
https://notcve.org/view.php?id=CVE-2023-25039
Missing Authorization vulnerability in CodePeople Google Maps CP.This issue affects Google Maps CP: from n/a through 1.0.43. Vulnerabilidad de autorización faltante en CodePeople Google Maps CP. Este problema afecta a Google Maps CP: desde n/a hasta 1.0.43. The Google Maps CP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the feedback_action function called via the cp-google-maps-feedback action in versions up to, and including, 1.0.43. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to perform an unauthorized feedback form submission. • https://patchstack.com/database/vulnerability/codepeople-post-map/wordpress-google-maps-cp-plugin-1-0-43-missing-authorization-leading-to-feedback-submission-vulnerability?_s_id=cve • CWE-862: Missing Authorization •