What3words maintains a location-identification service centered on its autosuggest product, a geocoding tool that processes user input to translate three-word addresses into geographic coordinates. The observed vulnerability signal reflects information-disclosure weaknesses in the handling of location and user data, a structural concern for services that aggregate and expose sensitive geolocation information.
The number and severity of CVEs published that impact products developed by What3words over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-4428HIGH A vulnerability has been found in what3words Autosuggest Plugin up to 4.0.0 on WordPress and classified as problematic. Affected by this vulnerability is the function enqueue_scrip | Jul 18, 2023 | 7.5 | 32 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by What3words.
Media articles that mention a CVE ID that affects a product developed by What3words — matched by CVE ID, not by vendor name.