Impact
The WordPress MapSVG Lite plugin contains an improper control of code generation flaw that permits arbitrary shortcode execution. This code injection vulnerability allows an attacker to inject malicious PHP code via shortcode processing, potentially compromising the entire WordPress site. The weakness corresponds to CWE‑94, which is inherently a code injection issue affecting confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects RomanCode’s MapSVG Lite plugin versions up through 8.6.9. Any WordPress installation running the plugin at 8.6.9 or earlier is susceptible; versions later than 8.6.9 are presumed untainted as no further details are provided.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while the EPSS score of less than 1 % suggests low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be web‑based, where an adversary can submit malicious shortcode content through the WordPress admin interface or by compromising a user account with shortcode insertion permissions, leading to execution of arbitrary PHP code on the server.
OpenCVE Enrichment
EUVD