Impact
The vulnerability is a missing authorization flaw in the WP Map Plugins Interactive Regional Map of Florida. Attackers can exploit incorrectly configured access control security levels, potentially gaining the ability to modify or delete map data and configuration settings. This unauthorized access could enable further misuse of the WordPress site, such as uploading malicious content or escalating privileges.
Affected Systems
WordPress plugin Interactive Regional Map of Florida from any version up to 1.0 is affected. The plugin is distributed by WP Map Plugins and is used in WordPress sites that include the Interactive Regional Map of Florida feature.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk. The EPSS score of less than 1% shows low likelihood of exploitation. It is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is inferred to be through the plugin’s web interface, requiring authenticated access or exploiting publicly exposed endpoints. This flaw could be leveraged by an attacker with access to a vulnerable instance to modify access control settings or retrieve sensitive configuration.
OpenCVE Enrichment
EUVD