Impact
The vulnerability allows an unauthenticated attacker to trigger a denial of service in the WP Go Maps WordPress plugin when the version is 10.1.08 or earlier. By exploiting the unchecked input handling documented as CWE‑770, an attacker can cause the plugin to consume excessive system resources, rendering the affected WordPress site unusable. The impact is strictly on availability, as there is no direct path to data compromise or code execution. The CVSS score of 5.3 classifies the issue as moderate severity. The exploit requires only unauthenticated access to the plugin’s web interface.
Affected Systems
Any WordPress installation using the WP Go Maps plugin version 10.1.08 or earlier is affected. The vulnerability is specific to the WPGMaps:WP Go Maps plugin and does not extend to other WordPress components unless they integrate the same plugin logic. If the site has not applied the recommended update to version 10.1.09 or newer, it remains exposed.
Risk and Exploitability
With a CVSS of 5.3, the risk is moderate. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no currently known widespread exploitation. Based on the description, the attack vector is inferred to be a web‑based request that does not require authentication, allowing an attacker to create resource‑intensive operations. The vulnerability’s exploitability thus largely depends on the site’s exposure to the Internet and its ability to throttle or limit such requests.
OpenCVE Enrichment