Description
WordPress Plugin MapPress Maps for WordPress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently download or delete arbitrary PHP files, or upload arbitrary malicious PHP files. WordPress Plugin MapPress Maps for WordPress version 2.54.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.54.6 or latest
References
Related Vulnerabilities
MySQL CVE-2021-2048 Vulnerability (CVE-2021-2048)
Oracle Application Server Other Vulnerability (CVE-2006-5358)
markdown-it Inefficient Regular Expression Complexity Vulnerability (CVE-2022-21670)
Oracle JRE CVE-2019-2973 Vulnerability (CVE-2019-2973)
WordPress Plugin STT2 Extension Add Terms Unspecified Vulnerability (1.0.2)