Impact
The MapSVG plugin for WordPress suffered a broken access control flaw that allows users to invoke functionality that should be restricted by access control lists. Specifically, the missing authorization check enables unauthorized users to perform actions otherwise limited to certain roles or administrators. The weakness is identified as CWE-862, indicating a failure to enforce appropriate permissions.
Affected Systems
This issue impacts the RomanCode MapSVG plugin on WordPress installations. Versions from the earliest available release through any version prior to 8.6.13 are affected. Users who have not yet upgraded to 8.6.13 or newer remain vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating a high threat. The EPSS score is below 1%, reflecting a low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker would likely exploit publicly reachable plugin endpoints to invoke unauthorized functions, possibly requiring a normal user account or access to the site’s admin interface; no detailed attack path is documented.
OpenCVE Enrichment
EUVD