CVE-2023-0037 describes a critical SQL injection vulnerability in the 10Web Map Builder for Google Maps WordPress plugin versions prior to 1.0.73. This flaw allows unauthenticated attackers to inject malicious SQL queries due to improper sanitization and escaping of parameters within an AJAX action. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with low attack complexity, potentially leading to full compromise of confidentiality, integrity, and availability. While not currently listed on CISA's KEV catalog or the Hot List, and with no known Metasploit or ExploitDB modules, Nuclei templates for this unauthenticated SQL injection exist, indicating readily available exploit code. Despite its high severity, there is currently no significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.73CPE matchmatch criteria | cpe:2.3:a:10web:map_builder_for_google_maps:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.