WP GPX Maps <= 1.7.08 - Authenticated (Contributor+) Stored Cross-Site Scripting via sgpx Shortcode
medium
The WP GPX Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sgpx' shortcode in all versions up to, and including, 1.7.08 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-le...
- CVSS:
- 6.4
- Affected:
- up to 1.7.08
- Fixed in:
- 1.7.10
- Disclosed:
- Sep 24, 2024
CVE-2024-9028 on NVD →
WP GPX Map <= 1.7.05 - Missing Authorization
medium
The WP GPX Map plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpgpxmaps_dismiss_notice() function in versions up to, and including, 1.7.05. This makes it possible for authenticated attackers, with subscriber-level access and above, to dismiss plugin noti...
- CVSS:
- 4.3
- Affected:
- up to 1.7.05
- Fixed in:
- 1.7.06
- Disclosed:
- Sep 29, 2023
CVE-2023-44234 on NVD →
WP GPX Maps < 1.1.23 - Arbitrary File Upload
critical
WordPress WP GPX Maps Plugin before 1.1.23 allows remote attackers to execute arbitrary PHP code via improper file upload.
- CVSS:
- 9.8
- Affected:
- up to 1.1.23
- Fixed in:
- 1.1.23
- Disclosed:
- Jun 11, 2012
CVE-2012-6649 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database