5.3
CVE-2025-11703
- EPSS 0.21%
- Veröffentlicht 18.10.2025 06:42:46
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
WP Go Maps (formerly WP Google Maps) <= 9.0.48 - Unauthenticated Cache Poisoning
WP Go Maps (formerly WP Google Maps) <= 9.0.48 - Unauthenticated Cache Poisoning
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48. This is due to the plugin not serving cached data from server-side responses and instead relying on user-input. This makes it possible for unauthenticated attackers to poison the cache location for location search results.
Mögliche Gegenmaßnahme
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map: Update to version 9.0.49, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerwpgmaps
≫
Produkt
WP Go Maps (formerly WP Google Maps)
Default Statusunaffected
Version <=
9.0.48
Version
0
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map
Version
*-9.0.48
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.115 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
CWE-349 Acceptance of Extraneous Untrusted Data With Trusted Data
The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.
https://www.wordfence.com/threat-intel/vulnerabilities/id/531360c6-e78a-4344-be06-95735337a2d6?source=cve
https://research.cleantalk.org/cve-2025-11703
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3378871%40wp-google-maps&new=3378871%40wp-google-maps&sfp_email=&sfph_mail=
https://github.com/CodeCabin/wp-google-maps/pull/1087/files
https://www.wordfence.com/threat-intel/vulnerabilities/id/531360c6-e78a-4344-be06-95735337a2d6