VYPR
Medium severity5.0NVD Advisory· Published Apr 9, 2025· Updated Apr 23, 2026

CVE-2025-32684

CVE-2025-32684

Description

Missing Authorization vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MapSVG: from n/a through <= 8.6.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

Root cause

"Missing authorization checks allow users with low privileges to access resources or perform actions that should require higher-level permissions."

Attack vector

An authenticated attacker with low privileges can exploit missing authorization checks [CWE-862] to access resources or perform actions that should require higher-level permissions. The attack is network-based (CVSS AV:N) with low complexity and no special authentication requirements beyond a basic user account. The impact is limited to low confidentiality exposure due to the incorrectly configured access control security levels.

Affected code

The advisory does not specify exact file paths or functions. The vulnerability is in the MapSVG plugin for WordPress (mapsvg-lite-interactive-vector-maps) versions through 8.6.4.

What the fix does

The advisory does not include a published patch. The plugin's changelog [ref_id=1] shows security fixes in subsequent versions (e.g., 8.6.5 'Fixed XSS vulnerability', 8.6.10 'Fixed security vulnerabilities related to unauthorized shortcode rendering in templates', 8.6.12 'Fixed a few vulnerabilities'), but none explicitly reference CVE-2025-32684. Users should update to the latest available version (8.13.2) which likely contains the necessary authorization checks.

Preconditions

  • authAttacker must have a low-privileged WordPress user account (e.g., subscriber or contributor)
  • configThe MapSVG plugin version 8.6.4 or earlier must be installed and active
  • networkNetwork access to the WordPress site is required

Generated on Jun 20, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

1

News mentions

0

No linked articles in our index yet.