Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f9fr-2hr3-67mf

Опубликовано: 15 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The WP Go Maps WordPress plugin before 10.0.10 does not properly enforce the marker approval filter on the admin-ajax fallback for its datatables route, allowing unauthenticated visitors to retrieve marker records that the site owner has not approved for public display, including their title, category, address and description fields.

The WP Go Maps WordPress plugin before 10.0.10 does not properly enforce the marker approval filter on the admin-ajax fallback for its datatables route, allowing unauthenticated visitors to retrieve marker records that the site owner has not approved for public display, including their title, category, address and description fields.

EPSS

Процентиль: 52%
0.00762
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
nvd
около 2 месяцев назад

The WP Go Maps WordPress plugin before 10.0.10 does not properly enforce the marker approval filter on the admin-ajax fallback for its datatables route, allowing unauthenticated visitors to retrieve marker records that the site owner has not approved for public display, including their title, category, address and description fields.

EPSS

Процентиль: 52%
0.00762
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200