VYPR

Leaflet Map

by Leaflet Map Project

CVEs (1)

  • CVE-2021-24467MedAug 9, 2021
    risk 0.42cvss 6.5epss 0.01

    The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows attackers to make a logged in admin update the settings via a Cross-Site Request Forgery attack. This could lead to Cross-Site Scripting issues by either changing…