Impact
MapSVG plugin versions up to 8.14.0 allow an authenticated administrative user to upload files without type, including executable scripts, which can be run on the web server. If an attacker can place a malicious script on the server, they can gain remote code execution, compromising the entire WordPress installation and potentially the underlying operating system. The weakness corresponds Upload of File with Dangerous Type.
Affected Systems
WordPress sites that use the MapSVG plugin in versions 8.14.0 or earlier are affected. The issue is specific to the MapSVG plugin component, not to WordPress core or other plugins.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that the probability of exploitation is low at the moment, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the flaw requires administrative authentication, an attacker who compromises or hijacks an admin account, or who has local access to the site, can exploit the upload shortcut. Once a malicious file is successfully uploaded, it can be executed, reading, modifying, or deleting site data and possibly backdooring the server.
OpenCVE Enrichment