Impact
The vulnerability in the RomanCode MapSVG plugin allows an attacker to inject malicious scripts into a WordPress site through DOM‑based cross‑site scripting. By delivering unsanitized input that is later reflected in the generated page, an attacker can run arbitrary code in the context of the site, potentially stealing session data, defacing content or executing further malicious actions.
Affected Systems
Any WordPress installation that uses the RomanCode MapSVG Lite plugin with a version 8.6.6 or older is affected. The vulnerability is present in all releases from the earliest documented version up through 8.6.6.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests that exploitation is currently rare, and the vulnerability has not been listed in CISA’s KEV catalog. The likely attack vector is the entry of malicious content via the plugin’s input fields, which is not properly escaped before rendering in the browser. An attacker who succeeds may execute scripts on the site’s pages and compromise user data.
OpenCVE Enrichment
EUVD