📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global data_breach Healthcare CRITICAL 1h Global vulnerability Information Technology and Telecommunications CRITICAL 1h Global vulnerability Information Technology / Networking HIGH 2h Global vulnerability Web Hosting / Government CRITICAL 2h Global general Technology and Digital Platforms HIGH 10h Global malware Multiple sectors HIGH 11h Global vulnerability Information Technology and Remote Support Services CRITICAL 12h Global apt Defense, Research, Healthcare, Academic CRITICAL 12h Global malware Software Development / Technology CRITICAL 12h Global vulnerability Technology/Software CRITICAL 12h Global data_breach Healthcare CRITICAL 1h Global vulnerability Information Technology and Telecommunications CRITICAL 1h Global vulnerability Information Technology / Networking HIGH 2h Global vulnerability Web Hosting / Government CRITICAL 2h Global general Technology and Digital Platforms HIGH 10h Global malware Multiple sectors HIGH 11h Global vulnerability Information Technology and Remote Support Services CRITICAL 12h Global apt Defense, Research, Healthcare, Academic CRITICAL 12h Global malware Software Development / Technology CRITICAL 12h Global vulnerability Technology/Software CRITICAL 12h Global data_breach Healthcare CRITICAL 1h Global vulnerability Information Technology and Telecommunications CRITICAL 1h Global vulnerability Information Technology / Networking HIGH 2h Global vulnerability Web Hosting / Government CRITICAL 2h Global general Technology and Digital Platforms HIGH 10h Global malware Multiple sectors HIGH 11h Global vulnerability Information Technology and Remote Support Services CRITICAL 12h Global apt Defense, Research, Healthcare, Academic CRITICAL 12h Global malware Software Development / Technology CRITICAL 12h Global vulnerability Technology/Software CRITICAL 12h
Vulnerabilities

CVE-2026-3581

Medium
CWE-862 — Weakness Type
Published: Apr 16, 2026  ·  Modified: Apr 19, 2026  ·  Source: NVD
CVSS v3
5.3
🔗 NVD Official
📄 Description (English)

The Basic Google Maps Placemarks plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.10.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify stored map latitude and longitude options.

🤖 AI Executive Summary

The Basic Google Maps Placemarks WordPress plugin versions up to 1.10.7 contains an authorization bypass vulnerability allowing unauthenticated attackers to modify map coordinates. This CWE-862 flaw enables unauthorized changes to stored latitude and longitude settings without proper user verification.

📄 Description (Arabic)

تحتوي إضافة Basic Google Maps Placemarks لـ WordPress على ثغرة تجاوز تفويض تسمح للمهاجمين غير المصرح لهم بتعديل خيارات خط العرض والطول المخزنة. تنشأ المشكلة من فشل الإضافة في التحقق بشكل صحيح من تفويض المستخدم قبل تنفيذ الإجراءات. قد يؤدي هذا إلى تعديل غير مصرح به لبيانات موقع الخريطة على مواقع WordPress المتأثرة.

🤖 ملخص تنفيذي (AI)

The Basic Google Maps Placemarks WordPress plugin versions up to 1.10.7 contains an authorization bypass vulnerability allowing unauthenticated attackers to modify map coordinates. This CWE-862 flaw enables unauthorized changes to stored latitude and longitude settings without proper user verification.

🤖 AI Intelligence Analysis Analyzed: May 30, 2026 05:03
🇸🇦 Saudi Arabia Impact Assessment
Saudi Relevance: medium
🏢 Affected Saudi Sectors
government telecom healthcare
🎯 MITRE ATT&CK Techniques
⚖️ Saudi Risk Score (AI)
5.0
/ 10.0
🔧 Remediation Steps (English)
Update the Basic Google Maps Placemarks plugin to version 1.10.8 or later immediately. Disable the plugin if immediate updates are unavailable. Review WordPress user roles and implement capability checks for map modification functions. Monitor WordPress logs for unauthorized map coordinate changes.
🔧 خطوات المعالجة (العربية)
قم بتحديث إضافة Basic Google Maps Placemarks إلى الإصدار 1.10.8 أو أحدث فوراً. عطّل الإضافة إذا لم يكن التحديث متاحاً. راجع أدوار مستخدمي WordPress وطبّق فحوصات الصلاحيات لوظائف تعديل الخريطة. راقب سجلات WordPress للتغييرات غير المصرح بها في إحداثيات الخريطة.
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
5.1.1 5.1.2
🔵 SAMA CSF
AC-2 AC-3
🟡 ISO 27001:2022
A.9.1.1 A.9.2.1 A.9.2.5
📊 CVSS Score
5.3
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityN — None / Network
IntegrityL — Low / Local
AvailabilityN — None / Network
📋 Quick Facts
Severity Medium
CVSS Score5.3
CWECWE-862
EPSS0.02%
Exploit No
Patch ✗ No
Published 2026-04-16
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
5.0
/ 10.0 — Saudi Risk
Priority: MEDIUM
🏷️ Tags
CWE-862
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.