漏洞描述
WordPress Google Maps plugin before 7.11.18 contains a SQL injection vulnerability. The plugin includes /class.rest-api.php in the REST API and does not sanitize field names before a SELECT statement. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
wpscan.comhttps://wpscan.com/vulnerability/475404ce-2a1a-4d15-bf02-df0ea2afdaea↗wordpress.orghttps://wordpress.org/plugins/wp-google-maps/#developers↗plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/changeset?old_path=%2Fwp-google-maps&old=2061433&new_path=%2Fwp-google-maps&new=2061434&sfp_email=&sfph_mail=#file755↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2019-10692↗github.comhttps://github.com/VTFoundation/vulnerablewp↗