Impact
The flaw allows an unauthenticated attacker to request arbitrary files from the server, potentially exposing sensitive configuration data, credentials, or other secrets. The vulnerable code in Geo Mashup does not properly sanitize file paths, leading to the inclusion of files not intended for public access.
Affected Systems
WordPress installations that have the Geo Mashup plugin from Dylan Kuhn with a version of 1.13.18 or earlier. The plugin is used to map geographic data, and it may be present on many sites. Users of these specific versions are directly impacted.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.1, indicating high severity. No EPSS score is available, but the lack of authentication requirements makes it attractive for automated exploitation. The vulnerability is not currently listed in the CISA KEV catalog, suggesting no known widespread attacks yet, yet the high score and unrestricted access vector imply significant risk.
OpenCVE Enrichment