Impact
An incorrect assignment of privileges in RomanCode's MapSVG plugin permits an attacker to increase their privileges within a WordPress installation. The flaw is classified as CWE-266 and allows an individual to gain higher authority, potentially enabling unauthorized configuration changes, content manipulation, or other actions reserved for administrators.
Affected Systems
The RomanCode MapSVG plugin, versions prior to 8.6.13, are affected. Any WordPress site running MapSVG 8.6.12 or earlier may be vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. With an EPSS score of less than 1% the likelihood of exploitation is currently low, and the flaw is not listed in CISA's KEV catalog. No specific attack vector is provided in the advisory; it is inferred that the vulnerability may be triggered via authenticated access or by manipulating privileged endpoints within the plugin. The impact is limited to WordPress environments that host the affected MapSVG plugin.
OpenCVE Enrichment
EUVD