<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Exploit Intel — cwe-89</title><link>https://exploit-intel.com/blog/tags/cwe-89/</link><description>EIP research articles tagged cwe-89.</description><language>en-us</language><atom:link href="https://exploit-intel.com/blog/tags/cwe-89/index.xml" rel="self" type="application/rss+xml"/><lastBuildDate>Sun, 29 Mar 2026 00:00:00 -0400</lastBuildDate><item><title>WP Google Map Plugin - Three Weak Links, One Critical Chain</title><link>https://exploit-intel.com/blog/posts/wp-google-map-plugin/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/wp-google-map-plugin/</guid><description>Line 781 says $query_to_run is safe. It isn't. An autonomous pipeline found a CVSS 9.8 unauthenticated SQL injection in WP Google Map Plugin v4.9.1 -- a three-link chain of individually harmless components that, together, give any visitor full database access. Then we kept reading and found the plugin deserializes update-check responses from an external server with maybe_unserialize(). 200,000+ active installs. 35 minutes. $8.97.</description><pubDate>Sun, 29 Mar 2026 00:00:00 -0400</pubDate></item></channel></rss>
