CVE-2012-10018

HIGH EXPLOITED NUCLEI

Mapplic & Mapplic Lite <6.1-1.0 - SSRF

Title source: llm

Description

The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes it possible for attackers to forgery requests coming from a vulnerable site's server and ultimately perform an XSS attack if requesting an SVG file.

Nuclei Templates (1)

WordPress Mapplic <= 6.1 / Mapplic Lite <= 1.0 - Authenticated Stored XSS via SVG File Upload
HIGHVERIFIEDby KrE80r

Scores

CVSS v3 8.3
EPSS 0.0338
EPSS Percentile 87.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

Details

VulnCheck KEV 2024-10-15
CWE
CWE-918
Status published
Products (4)
mapplic/mapplic < 1.0
mapplic/mapplic < 6.1
sekler/Mapplic - Custom Interactive Map WordPress Plugin < 6.2
sekler/Mapplic Lite < 1.0.1
Published Oct 16, 2024
Tracked Since Feb 18, 2026