Impact
This vulnerability allows an attacker to inject arbitrary SQL statements through the WordPress WP Maps plugin’s administrator interface. The injection flaw permits reading, modifying, or deleting database contents, potentially exposing sensitive data or corrupting site content. The weakness lies in improper validation of user input before database execution, as identified by CWE-89.
Affected Systems
The flaw affects installations of the Flipper Code WP Maps WordPress plugin with versions 4.9.9 and earlier. Users running any update prior to 5.0.0 are vulnerable. The vulnerability is specific to the WP Maps plugin and does not extend to other WordPress components.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity with an impact that can be mitigated by patching. The EPSS score is not available, so real‑world exploitation probability is unknown; however, the flaw is publicly documented and the KEV status is not listed, implying no known active exploits at this time. Attackers who can reach the admin interface or possess administrative credentials can potentially exploit the injection point to compromise the database. If an attacker gains control of the database, they could exfiltrate data or inject malicious content, affecting confidentiality, integrity, and availability of the site.
OpenCVE Enrichment