Description
Missing Authorization vulnerability in ldwin79 sourceplay-navermap sourceplay-navermap allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects sourceplay-navermap: from n/a through <= 0.0.2.
Published: 2025-03-24
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability lies in a missing authorization check that enables an attacker to bypass the configured access control levels of the sourceplay-navermap WordPress plugin. The flaw permits unauthorized exploration or manipulation of protected resources that should be available only to privileged users. The primary consequence is the potential for an attacker to gain inappropriate access to sensitive data or functionality within the WordPress site without needing any valid credentials.

Affected Systems

The flaw affects the sourceplay-navermap plugin distributed by ldwin79 for WordPress, specifically all releases from the initial release through version 0.0.2. Users running any of these versions on a WordPress site are vulnerable, regardless of the site’s overall configuration or user base. No other WordPress components are directly mentioned as impacted.

Risk and Exploitability

The CVSS base score of 4.3 classifies the vulnerability as moderate, indicating that while the attack does not compromise the entire system, it can expose privileged functionalities. The EPSS score, being below 1%, suggests that the probability of real-world exploitation is low at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote and involves interacting with the plugin’s web interfaces, potentially through crafted requests that exploit the missing authorization check. No specific prerequisites beyond access to the WordPress site are stated, so normal connectivity to the site is sufficient to potentially exploit the flaw.

Generated by OpenCVE AI on May 1, 2026 at 04:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the sourceplay-navermap plugin to the latest available version that remediates the missing authorization check; if an update is not yet released, replace the plugin with a vetted alternative that implements proper role‑based access control.
  • Reconfigure the WordPress user roles to limit the number of users with capabilities that interact with the plugin, effectively reducing the attack surface for this vulnerability.
  • Apply network‑level controls or web‑application firewall rules to block suspicious or unauthorized access patterns that could target the plugin’s endpoints, and monitor logs for unauthorized activity tied to sourceplay-navermap.

Generated by OpenCVE AI on May 1, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-7926 Missing Authorization vulnerability in ldwin79 sourceplay-navermap allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects sourceplay-navermap: from n/a through 0.0.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in ldwin79 sourceplay-navermap allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects sourceplay-navermap: from n/a through 0.0.2. Missing Authorization vulnerability in ldwin79 sourceplay-navermap sourceplay-navermap allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects sourceplay-navermap: from n/a through <= 0.0.2.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Mon, 24 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Mar 2025 14:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in ldwin79 sourceplay-navermap allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects sourceplay-navermap: from n/a through 0.0.2.
Title WordPress sourceplay-navermap plugin <= 0.0.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:55.235Z

Reserved: 2025-03-24T13:00:39.013Z

Link: CVE-2025-30605

cve-icon Vulnrichment

Updated: 2025-03-24T15:40:46.772Z

cve-icon NVD

Status : Deferred

Published: 2025-03-24T14:15:33.103

Modified: 2026-04-23T15:26:57.477

Link: CVE-2025-30605

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T04:30:08Z

Weaknesses