PT-2022-9544 · WordPress · Osmapper Wordpress Plugin

Dc11

·

Published

2022-03-28

·

Updated

2022-10-25

·

CVE-2021-24978

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OSMapper WordPress plugin versions 2.1.5 and earlier
Description The issue allows unauthenticated users to delete arbitrary posts from a blog due to an AJAX action in the OSMapper WordPress plugin that lacks authorization, CSRF checks, and proper validation to ensure only 'map' post types can be deleted. This makes the plugin's delete functionality accessible without proper restrictions, potentially leading to unauthorized post deletion.
Recommendations For OSMapper WordPress plugin versions 2.1.5 and earlier, consider disabling the AJAX action related to post deletion until a patch is available. Restrict access to the wp ajax nopriv prefix to minimize the risk of exploitation. Avoid using the plugin's delete functionality for post types other than 'map' until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

CSRF

Weakness Enumeration

Related Identifiers

CVE-2021-24978

Affected Products

Osmapper Wordpress Plugin