Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-8386

Опубликовано: 15 июн. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve marker records that an administrator has not yet approved for public display, including any PII placed in the address and description fields and the marker's geographic coordinates.

EPSS

Процентиль: 50%
0.007
Низкий

5.3 Medium

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 5.3
github
около 2 месяцев назад

The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve marker records that an administrator has not yet approved for public display, including any PII placed in the address and description fields and the marker's geographic coordinates.

EPSS

Процентиль: 50%
0.007
Низкий

5.3 Medium

CVSS3

Дефекты