Impact
The vulnerability is a broken access control flaw in the WP Go Maps plugin for WordPress, affecting versions 10.1.04 and earlier. An unauthenticated attacker can gain unauthorized access to the plugin’s administrative interfaces or manipulate data stored by the plugin. This flaw falls under CWE‑862 and allows the attacker to read or modify map settings, potentially leading to loss of confidentiality, integrity, or availability of map data.
Affected Systems
The issue impacts the WPGMaps: WP Go Maps plugin for WordPress, specifically all releases up to and including version 10.1.04. Users operating that plugin on any WordPress installation are therefore affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while the EPSS score of less than 1 % suggests a very low exploitation probability at present. The plugin’s own administrative URLs can be accessed without authentication, providing a likely attack path for a remote attacker. Because the vulnerable code is part of a WordPress plugin, the impact scope includes the entire WordPress site’s configuration and any data stored by the plugin, though the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment