Record summary

CVE-2019-10692 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

MetasploitWordPress Google Maps Plugin SQL InjectionMetasploit auxiliary PoCby Thomas Chauchefoin (Synacktiv)Not analyzed1 file

Ruby

Metasploit

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress Google Maps <7.11.18 - SQL InjectionCVSS 9.8

WordPress Google Maps plugin before 7.11.18 contains a SQL injection vulnerability. The plugin includes /class.rest-api.php in the REST API and does not sanitize field names before a SELECT statement. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability could lead to unauthorized access to the WordPress database.

Remediation

Update to the latest version of the WordPress Google Maps plugin (7.11.18 or higher).

WeaknessesCWE-89
Authorspussycat0x
Template tagscve2019cvewpwp-pluginunauthsqliwordpressgooglemapswpscancodecabinvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:codecabin:wp_go_maps:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

5