Impact
The MapSVG plugin for WordPress is vulnerable because user supplied attributes within the map options are not properly sanitized or escaped. Authenticators holding contributor‑level or higher privileges can store malicious JavaScript in these options. When any user later views a page containing the affected map, the injected script executes in that user’s browser, giving the attacker the ability to steal session cookies, modify page content, or perform other client‑side attacks.
Affected Systems
All installations of the MapSVG plugin distributed by Oyatek, up to and including version 8.14.0, are affected.
Risk and Exploitability
With a CVSS score of 6.4 the vulnerability is of moderate severity. The EPSS score is below 1 %, indicating a low likelihood of known exploitation at this time, and the flaw is not listed in CISA’s KEV catalog. The attack requires authenticated access with at least contributor privileges and exploitation occurs via a stored script that runs in the victim’s browser when the compromised map is loaded.
OpenCVE Enrichment