PT-2020-13196 · WordPress · Mappress-Google-Maps-For-Wordpress

Published

2020-05-29

·

Updated

2023-02-09

·

CVE-2020-12675

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mappress-google-maps-for-wordpress plugin versions prior to 2.54.6
Description The issue is related to incomplete capability checks for AJAX functions, specifically those involved in the creation, retrieval, and deletion of PHP template files. This incomplete check leads to Remote Code Execution. The problem arose from an incomplete fix for a previous issue.
Recommendations For versions prior to 2.54.6, update to version 2.54.6 or later to resolve the issue.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2020-12675

Affected Products

Mappress-Google-Maps-For-Wordpress