Record summary

CVE-2023-0037 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 3, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 27, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

10Web Map Builder for Google Maps

Default status: unaffected

CVE ListBefore 1.0.73affected

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress 10Web Map Builder < 1.0.73 - Unauthenticated SQL InjectionCVSS 9.8

The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

Impact

Unauthenticated attackers can execute SQL injection through AJAX actions to extract the complete WordPress database including user credentials, map configuration data, and sensitive site information.

Remediation

Fixed in 1.0.73

WeaknessesCWE-89
Authorsriteshs4hu
Template tagswpscancvecve2023wordpresswp-pluginwpwd-google-mapssqlitime-basedvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:10web:map_builder_for_google_maps:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3