Impact
The RomanCode MapSVG WordPress plugin contains a flaw that allows contributors to inject arbitrary JavaScript into map data. Because the plugin renders map content in visitors’ browsers without proper output sanitization, an attacker who can edit a map can trigger cross‑site scripting in any user that views the compromised map. This does not provide server‑side access, but it does allow malicious scripts to run in the context of the site’s domain, enabling potential phishing, credential theft, or other client‑side attacks
Affected Systems
Any WordPress site that has installed the RomanCode MapSVG plugin version 8.14.0 or earlier is affected. The vulnerability applies only to the plugin’s map editing functionality; other WordPress components are not impacted. The risk exists when the plugin is active and contributors are permitted to edit map content
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity. The EPSS score of less than 1% indicates that widespread exploitation is unlikely in the current landscape. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a contributor who is able to add or modify map data; by inserting malicious JavaScript code, such a user can cause XSS when a victim loads the altered map. No additional authentication or privilege escalation is required beyond contributor rights.
OpenCVE Enrichment