Impact
The vulnerability is a contributor‑driven SQL Injection flaw present in MapSVG plugin versions 8.14.0 and earlier. Attackers can submit crafted input that is unsafely integrated into database queries, enabling them to read, modify, or delete database contents. This compromises the confidentiality and integrity of the data stored by affected WordPress sites, and could provide a foothold for further exploitation if administrative privileges are gained.
Affected Systems
The flaw affects the RomanCode MapSVG WordPress plugin for all releases up to and including version 8.14.0. WordPress sites that have installed any of these versions are vulnerable, regardless of the underlying WordPress core version.
Risk and Exploitability
The CVSS v3 score of 8.5 classifies this as a high‑severity issue. The EPSS figure of less than 1 % indicates that exploitation attempts are currently infrequent, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a web request that includes malicious SQL payloads; based on the description it is inferred that the vulnerability can be triggered from the front‑end or back‑end interfaces of the plugin.
OpenCVE Enrichment