CVE-2025-23913

CVSS 3.1 Score 8.5 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 89

Summary

CVE-2025-23913 represents a significant security vulnerability in the WordPress Google Map Professional plugin, specifically an SQL Injection issue. This defect arises from the plugin's failure to properly neutralize special characters in SQL commands, making it susceptible to malicious SQL injection attacks. This vulnerability, which affects WordPress Google Map Professional versions from n/a through 1.0, can potentially enable attackers to gain unauthorized access to sensitive data or even take control of the affected WordPress site.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share