CVE-2019-1000003
Expert Analysis
Professional remediation guidance
Get tailored security recommendations from our analyst team for CVE-2019-1000003. We'll provide specific mitigation strategies based on your environment and risk profile.
Description
MapSVG MapSVG Lite version 3.2.3 contains a Cross Site Request Forgery (CSRF) vulnerability in REST endpoint /wp-admin/admin-ajax.php?action=mapsvg_save that can result in an attacker can modify post data, including embedding javascript. This attack appears to be exploitable via the victim must be logged in to WordPress as an admin, and click a link. This vulnerability appears to have been fixed in 3.3.0 and later.
Available Exploits
Related News
WordPress Vulnerability
Identified and analyzed by Wordfence
Software Type
Patch Status
Published
Software Details
Software Name
MapSVG – Vector maps, Image maps, Google Maps
Software Slug
mapsvg-lite-interactive-vector-maps
Affected Versions
Patched Versions
Remediation
Update to version 3.3.0, or a newer patched version
© Defiant Inc. Data provided by Wordfence.
GitHub Security Advisories
Community-driven vulnerability intelligence from GitHub
Advisory Details
CVSS Scoring
CVSS Score
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References
Advisory provided by GitHub Security Advisory Database. Published: May 14, 2022, Modified: May 14, 2022