WordPress Plugin Vulnerabilities

Map Block for Google Maps < 1.32 - Unauthorised Google API Key change

Description

The gmw_map_block_save_key AJAX action, available to both authenticated and unauthenticated users did not have any check in place to prevent unauthorised change of the Google API key.

Proof of Concept

Affects Plugins

Fixed in 1.32

References

Classification

Type
ACCESS CONTROLS
CWE

Miscellaneous

Verified
Yes

Timeline

Publicly Published
2021-02-10 (about 5 years ago)
Added
2021-02-10 (about 5 years ago)
Last Updated
2021-02-10 (about 5 years ago)

Other