Description
Missing Authorization vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MapSVG: from n/a through <= 8.6.4.
Published: 2025-04-09
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in RomanCode MapSVG’s mapsvg-lite-interactive-vector-maps plugin and is a missing authorization issue, classified as CWE-862. Because the plugin’s access control is improperly configured, users who should not have elevated privileges may gain access to restricted functions within the plugin. Based on the description, it is inferred that an attacker could modify, delete, or otherwise tamper with map data or configuration settings that are normally protected, thereby compromising data integrity and possibly exposing sensitive information embedded in maps.

Affected Systems

WordPress sites that have installed RomanCode MapSVG mapsvg-lite-interactive-vector-maps at any version up to and including 8.6.4 are affected. The plugin is commonly used to embed interactive vector maps, so any site served by WordPress that relies on this plugin and runs a vulnerable version is at risk.

Risk and Exploitability

The CVSS score of 5.0 places it in the moderate severity range, while the EPSS score of less than 1% indicates a very low probability of exploitation observed in the past. The flaw is not listed in the CISA KEV catalog. An attacker would most likely exploit the vulnerability through the web interface of the WordPress site, leveraging normal HTTP requests to trigger the incorrectly authorized actions. Since the plugin is a WordPress component, the attack vector is remote and requires either an authenticated session or the ability to reach the relevant plugin endpoints; detailed prerequisites are not specified in the description, but broken access control generally implies elevation of privileges within the application.

Generated by OpenCVE AI on May 1, 2026 at 10:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade RomanCode MapSVG to a version newer than 8.6.4
  • Restrict WordPress administrative access to trusted users and enforce least‑privilege policies
  • Implement a Web Application Firewall to block anomalous access patterns to the MapSVG plugin endpoints

Generated by OpenCVE AI on May 1, 2026 at 10:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10559 Missing Authorization vulnerability in RomanCode MapSVG Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MapSVG Lite: from n/a through 8.5.32.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in RomanCode MapSVG Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MapSVG Lite: from n/a through 8.5.32. Missing Authorization vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MapSVG: from n/a through <= 8.6.4.
Title WordPress MapSVG Lite plugin <= 8.5.32 - Broken Access Control Vulnerability WordPress MapSVG Lite plugin <= 8.6.4 - Broken Access Control Vulnerability
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}


Wed, 09 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Apr 2025 16:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in RomanCode MapSVG Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MapSVG Lite: from n/a through 8.5.32.
Title WordPress MapSVG Lite plugin <= 8.5.32 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:27.948Z

Reserved: 2025-04-09T11:21:24.366Z

Link: CVE-2025-32684

cve-icon Vulnrichment

Updated: 2025-04-09T17:43:11.308Z

cve-icon NVD

Status : Deferred

Published: 2025-04-09T17:15:52.640

Modified: 2026-04-23T15:29:20.790

Link: CVE-2025-32684

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T11:00:15Z

Weaknesses