The Add Multiple Marker plugin for WordPress is vulnerable to unauthorized modification of data to due to a missing capability check on the addmultiplemarker_reset_map() and amm_save_map_api() functions in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to update the map API and reset maps.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Krishaweb
Krishaweb add Multiple Marker Wordpress Wordpress wordpress |
|
| Vendors & Products |
Krishaweb
Krishaweb add Multiple Marker Wordpress Wordpress wordpress |
Tue, 11 Nov 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Add Multiple Marker plugin for WordPress is vulnerable to unauthorized modification of data to due to a missing capability check on the addmultiplemarker_reset_map() and amm_save_map_api() functions in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to update the map API and reset maps. | |
| Title | Add Multiple Marker <= 1.2 - Missing Authorization to Unauthenticated Settings Update | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-11-11T03:30:52.126Z
Updated: 2025-11-12T20:04:34.484Z
Reserved: 2025-10-20T20:57:46.854Z
Link: CVE-2025-11999
Updated: 2025-11-12T15:00:26.527Z
Status : Awaiting Analysis
Published: 2025-11-11T04:15:45.463
Modified: 2025-11-12T16:19:34.210
Link: CVE-2025-11999
No data.