Impact
This vulnerability is an unauthenticated Remote File Inclusion flaw in the Easy Google Maps plugin for WordPress. An attacker can supply a URL or path to a remote file, causing the plugin to fetch and execute that file within the context of the website. The plugin fails to validate or sanitize the file input, which can lead to execution of arbitrary code, compromising confidentiality, integrity, and availability.
Affected Systems
The affected system is the Easy Google Maps plugin from Supsystic. Versions prior to 1.14.2 are vulnerable. Site owners running an older version of the plugin on a WordPress installation are at risk.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this flaw without authentication by sending a crafted request to the plugin. Successful exploitation may allow execution of arbitrary code within the website context.
OpenCVE Enrichment