Security readout for executives and security teams
Plain-English summary
This CVE affects the WordPress wp-google-map-plugin before version 2.3.10. The reported issue is CSRF in the add/edit location feature, meaning an authenticated site user could potentially be tricked into making unintended map-location changes. Sources do not report code execution, data theft, or active exploitation.
Executive priority
Treat this as a targeted content-integrity risk, not an emergency based on current evidence. Prioritize remediation on public WordPress sites using the plugin, especially where map content affects customers, facilities, or brand trust.
Technical view
CVE-2015-9307 is a cross-site request forgery flaw in wp-google-map-plugin versions before 2.3.10, specifically in the add/edit location workflow. The public record does not provide CVSS, CWE mapping, role requirements, proof-of-concept details, or implementation-level root cause.
Likely exposure
Exposure is limited to WordPress sites that installed wp-google-map-plugin below 2.3.10 and use its location management features. The sources do not identify affected roles or whether the vulnerable action is admin-only.
Exploitation context
CISA KEV is false, and the supplied sources do not cite active exploitation. Practical abuse would likely depend on convincing an authenticated WordPress user with plugin privileges to submit an unintended add/edit location request.
Researcher notes
The source record is sparse. It names the vulnerable plugin, version boundary, and CSRF-affected feature, but omits CVSS, CWE, affected roles, exploit evidence, and patch mechanics. Avoid claiming broader WordPress compromise without additional vendor evidence.
Mitigation direction
- Upgrade wp-google-map-plugin to version 2.3.10 or later.
- Review the WordPress plugin changelog and vendor guidance.
- Remove the plugin if it is unused.
- Restrict WordPress administrative access to trusted users.
- Monitor map-location changes for unauthorized edits.
Validation and detection
- Inventory WordPress sites for wp-google-map-plugin installations.
- Confirm installed plugin versions are 2.3.10 or later.
- Review recent map-location additions and edits for anomalies.
- Check whether only trusted roles can manage plugin locations.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2015-9307 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://wordpress.org/plugins/wp-google-map-plugin/#developersCVE reference · x_refsource_MISC
- https://wpvulndb.com/vulnerabilities/9766CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
