Impact
The vulnerability is a broken access control flaw that may allow unauthenticated users to access or manipulate plugin resources that should be protected. The specific capabilities are not detailed in the CVE description, and this analysis does not assume that attackers can create or modify map entries. Based on the description, the flaw could affect the integrity and confidentiality of data managed by the plugin, but it does not grant system‑level privileges.
Affected Systems
The issue affects the WordPress Ultimate Maps by Supsystic plugin, versions 1.5.5 and earlier. Site owners running any of these versions on a WordPress installation are exposed. Upgrade to 1.6.1 or later resolves the problem.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability. EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The flaw can be exploited remotely via the web interface, and because it does not require authentication, privilege escalation is not required. Attackers could potentially access plugin functionality that should be restricted, leading to data exposure or tampering; however, the CVE description does not disclose the specific capabilities an attacker could gain. This analysis does not assume any particular action beyond what is stated.
OpenCVE Enrichment