PT-2022-9544 · WordPress · Osmapper Wordpress Plugin
Dc11
·
Published
2022-03-28
·
Updated
2022-10-25
·
CVE-2021-24978
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OSMapper WordPress plugin versions 2.1.5 and earlier
Description
The issue allows unauthenticated users to delete arbitrary posts from a blog due to an AJAX action in the OSMapper WordPress plugin that lacks authorization, CSRF checks, and proper validation to ensure only 'map' post types can be deleted. This makes the plugin's delete functionality accessible without proper restrictions, potentially leading to unauthorized post deletion.
Recommendations
For OSMapper WordPress plugin versions 2.1.5 and earlier, consider disabling the AJAX action related to post deletion until a patch is available. Restrict access to the wp ajax nopriv prefix to minimize the risk of exploitation. Avoid using the plugin's delete functionality for post types other than 'map' until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authorization
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Osmapper Wordpress Plugin