S4E just found an informational finding from tcp full port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2023-0037

9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

Attack Vector
Network
Privileges Req.
None
User Interaction
None
10web map builder for google maps
Updated Sep 26, 2026View on NVD →
S4E scanner

CVE-2023-0037 Scanner

Targets the AJAX action 'wpmap_builder_ajax' with unsanitized 'id' parameter, allowing unauthenticated attackers to extract arbitrary database contents.

Used 3.5k times · 3.3k assets checked · domain, subdomain, ipv4

CVE history: 10web map builder for google maps

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →