Impact
The CVE details a missing authorization flaw in the RomanCode MapSVG WordPress plugin that permits exploitation of incorrectly configured access control security levels. The weakness is defined as CWE-862, indicating improper enforcement of access controls. This flaw could allow an attacker to invoke protected plugin functions or access configuration data without proper authorization, though the exact extent of exposed data or actions is not specified.
Affected Systems
Any installation of the MapSVG plugin for WordPress produced by RomanCode with a version earlier than 8.6.13 is vulnerable, including all releases from the earliest available version up through 8.6.12.
Risk and Exploitability
The CVSS score of 5 signals a moderate severity, while the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not included in the CISA KEV catalog, reducing its current threat visibility. Because the description does not define a specific attack vector, the risk is assumed to involve interactions with the plugin’s web interfaces that lack proper access control checks.
OpenCVE Enrichment
EUVD