Impact
Unauthenticated broken access control in the Ultimate Maps by Supsystic WordPress plugin allows an attacker to read, modify, or delete map data and potentially other plugin settings without authentication. This flaw is a privilege escalation weakness (CWE‑862), compromising confidentiality, integrity, and availability of the site’s mapping content.
Affected Systems
The vulnerability affects all installations of WordPress Ultimate Maps by Supsystic that run versions older than 1.5.0. Site administrators should verify the plugin version and plan an upgrade if applicable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. EPSS data is not available and the flaw is not listed in CISA KEV, suggesting that large‑scale public exploits have not yet been observed. The likely attack vector is web‑based: any visitor to the site can trigger the flaw to elevate privileges within the plugin. Monitoring and timely patching remain crucial for mitigating this risk.
OpenCVE Enrichment