Impact
An unauthenticated SQL injection vulnerability exists in the WordPress MapSVG plugin version 8.14.0 and earlier. The flaw allows an attacker to inject arbitrary SQL code into database queries executed by the plugin, giving the potential to read, modify, or delete sensitive data stored in the WordPress database.
Affected Systems
The vulnerability affects the WordPress MapSVG plugin distributed by RomanCode. All releases up to and including version 8.14.0 are impacted. Users running the plugin on a WordPress site should be aware that the vulnerability exists in these versions.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity level, and the EPSS score of < 1% shows that the current exploitation probability is low. The issue is not listed in the CISA KEV catalog. The likely attack vector is inferred to be via unauthenticated HTTP requests directed at the plugin’s endpoints, allowing remote exploitation without needing valid credentials. This vulnerability may allow an attacker to read, modify, or delete data stored in the WordPress database, potentially leading to data loss or unauthorized database content modification.
OpenCVE Enrichment