Impact
The vulnerability is an unauthenticated Server Side Request Forgery (SSRF) affecting MapSVG plugin versions up to 8.15.0. An attacker can cause the WordPress site to send HTTP requests to arbitrary URLs, including internal network resources, potentially exposing sensitive data or enabling further attacks, such as internal enumeration or exploitation of other services. The weakness is the improper validation of user‑supplied URLs, which is identified as CWE‑918.
Affected Systems
Affected systems are WordPress sites that have the MapSVG plugin installed in any version 8.15.0 or earlier. The vendor/product is MapSVG:MapSVG. No precise version range beyond the upper bound is supplied, so all installations of MapSVG prior to 8.16.0 are considered vulnerable unless a patch has been applied.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is not available, so current exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. The typical attack path is that a remote attacker sends a crafted request to an exposed endpoint in the plugin, causing the server to fetch an attacker‑supplied URL. Because authentication is not required, the attack can be performed from any IP that can reach the site.
OpenCVE Enrichment