CVE-2023-0037
10WebMapBuilder < 1.0.73 - Unauthenticated SQLi
Record summary
CVE-2023-0037 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 3, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 27, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
map_builder_for_google_mapsBrowse 10web / map_builder_for_google_maps | VulnCheck | Version data not supplied | |
10Web Map Builder for Google MapsDefault status: unaffected | CVE List | Before 1.0.73 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALWordPress 10Web Map Builder < 1.0.73 - Unauthenticated SQL InjectionCVSS 9.8
The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
Impact
Unauthenticated attackers can execute SQL injection through AJAX actions to extract the complete WordPress database including user credentials, map configuration data, and sensitive site information.
Remediation
Fixed in 1.0.73
Source: ProjectDiscovery