CVE-2019-10692
In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement.
- Affected products
- Wp Google Maps
- Codecabin Wp Go Maps
- < 7.11.18
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 78.7% (100th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2019-04-02
CVE-2019-10692 at NVD
5 known exploits for CVE-2019-10692
Proof-of-concept code and exploit modules indexed by Sploitus