Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7gcf-rrgh-pw4q

Опубликовано: 15 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve marker records that an administrator has not yet approved for public display, including any PII placed in the address and description fields and the marker's geographic coordinates.

The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve marker records that an administrator has not yet approved for public display, including any PII placed in the address and description fields and the marker's geographic coordinates.

EPSS

Процентиль: 13%
0.00225
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
около 2 месяцев назад

The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve marker records that an administrator has not yet approved for public display, including any PII placed in the address and description fields and the marker's geographic coordinates.

EPSS

Процентиль: 13%
0.00225
Низкий

5.3 Medium

CVSS3