Impact
The vulnerability is a Path Traversal flaw that allows an attacker to download any files located on the server. Based on the description, when an attacker sends a crafted request to the Open User Map plugin, they can navigate the server's filesystem and retrieve arbitrarily selected files. This could expose sensitive configuration, database credentials or other private data. The flaw is documented as CWE-22 and carries a CVSS score of 6.5, indicating a moderate severity.
Affected Systems
Affected systems are the WordPress plugin Open User Map by 100plugins. Versions up to and including 1.4.16 are vulnerable; all newer releases are not affected.
Risk and Exploitability
The attack vector is remote over HTTP, requiring only the ability to send a request to the plugin endpoint. The EPSS score of <1% suggests that spontaneous exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 6.5 places it in the moderate severity range, meaning an attacker who succeeds could gain unauthorized file disclosure and potentially use the exposed files for further attacks.
OpenCVE Enrichment