Impact
The Mapster WP Maps plugin contains a flaw that lets an authenticated user alter any user’s meta data without performing nonce verification, capability checks, or input validation on the meta key supplied through the acf-photo-gallery-groups POST parameter. This flaw means that an attacker who can log into the site with Subscriber-level access or higher can freely write arbitrary key/value pairs into the user_meta table for any user account, potentially altering sensitive application data or setting values that future code may trust. The vulnerability is a classic input validation issue (CWE‑20) and results in a data integrity breach, but it does not provide privilege escalation to higher roles.
Affected Systems
The flaw affects all releases of the Mapster WP Maps plugin with version numbers up to and including 1.23.0. The affected product is the Mapster WP Maps plugin for WordPress, distributed by the vendor Mapster.
Risk and Exploitability
The CVSS score of 8.8 categorizes the issue as high severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, which reduces its prominence among known exploited weaknesses. The attack vector is likely network-based, requiring the attacker to be authenticated to the WordPress installation, so any user with a Subscriber role or higher can trigger the flaw by submitting a crafted POST request containing an acf-photo-gallery-groups parameter with an arbitrary meta key and value.
OpenCVE Enrichment