Missing Authorization Vulnerability in RomanCode's MapSVG Product
CVE-2025-47560

5MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
16 May 2025

What is CVE-2025-47560?

A missing authorization vulnerability in RomanCode's MapSVG product permits exploitation due to improperly configured access control security levels. This flaw allows unauthorized users to bypass expected security measures, potentially leading to data exposure or manipulation. The issue is observed in MapSVG versions from n/a to 8.5.32, emphasizing the need for users to review their access control settings to safeguard their applications.

Affected Version(s)

MapSVG <= 8.5.32

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anhchangmutrang (Patchstack Alliance)
.