CVE-2022-29453: WordPress API KEY for Google Maps plugin <= 1.2.1 - CSRF vulnerability leading to Google Maps API key update
Published Jun 15, 2022
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in API KEY for Google Maps plugin <= 1.2.1 at WordPress leading to Google Maps API key update.
Affected Software
1 affected component
AyeCode Api Key For Google Maps Wordpress<=1.2.1
Remediation
Information
Update to 1.2.2 or higher version.
Event History
Jun 15, 2022
CVE Published
via MITRE·03:16 PM
Data Sourced
via MITRE·03:16 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-29453?
CVE-2022-29453 is a Cross-Site Request Forgery (CSRF) vulnerability in the API KEY for Google Maps plugin <= 1.2.1 at WordPress leading to Google Maps API key update.
2
How severe is CVE-2022-29453?
CVE-2022-29453 has a severity rating of medium with a CVSS score of 4.3.
3
Which software versions are affected by CVE-2022-29453?
API KEY for Google Maps plugin versions up to and including 1.2.1 on WordPress are affected by CVE-2022-29453.
4
How can CVE-2022-29453 be exploited?
CVE-2022-29453 can be exploited through Cross-Site Request Forgery (CSRF) attacks, allowing an attacker to update the Google Maps API key.
5
Is there a fix for CVE-2022-29453?
Yes, a fix for CVE-2022-29453 is available. Update API KEY for Google Maps plugin to version 1.2.2 or later.