WordPress StoryMap Plugin Cross-Site Request Forgery Vulnerability Allowing SQL Injection

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress StoryMap plugin, specifically in versions through 2.1. This vulnerability allows for SQL Injection, as it could enable attackers to manipulate database queries and potentially access or modify database information.

Impact

Exploitation of this vulnerability could lead to SQL Injection, allowing attackers to interfere with database queries. This could result in unauthorized data access, data manipulation, or in some cases, executing administrative operations on the WordPress site.

Added: Aug 14, 2025, 8:35 PM
Updated: Aug 14, 2025, 8:35 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
6.4
remediation
0.0
relevance
0.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.