plugin

Mapsvg Vulnerabilities

22 known security issues reported for the Mapsvg WordPress plugin. Most recent disclosed Jul 23, 2026.

5 high 7 medium

Running Mapsvg on your site? Check whether your installed version is affected.

Scan your site free

MapSVG <= 8.14.0 - Unauthenticated SQL Injection

high

The MapSVG plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.14.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into alr...

CVSS:
7.5
Affected:
up to 8.14.0
Fixed in:
8.14.1
Disclosed:
Jul 23, 2026

CVE-2026-59526 on NVD →

MapSVG <= 8.14.0 - Authenticated (Contributor+) SQL Injection

medium

The MapSVG plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.14.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, t...

CVSS:
6.5
Affected:
up to 8.14.0
Fixed in:
8.14.1
Disclosed:
Jul 22, 2026

CVE-2026-65451 on NVD →

MapSVG [mapsvg] < 8.6.12

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RomanCode MapSVG mapsvg allows Path Traversal.This issue affects MapSVG: from n/a through < 8.6.12.

Affected:
up to 8.6.12
Fixed in:
8.6.12
Disclosed:
Dec 18, 2025

CVE-2025-54748 on NVD →

MapSVG [mapsvg] < 8.7.4

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RomanCode MapSVG allows SQL Injection. This issue affects MapSVG: from n/a through n/a.

Affected:
up to 8.7.4
Fixed in:
8.7.4
Disclosed:
Aug 14, 2025

CVE-2025-54669 on NVD →

MapSVG < 8.7.4 - Unauthenticated SQL Injection

high

The MapSVG plugin for WordPress is vulnerable to SQL Injection in versions up to 8.7.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing qu...

CVSS:
7.5
Affected:
up to 8.7.4
Fixed in:
8.7.4
Disclosed:
Aug 8, 2025

CVE-2025-54669 on NVD →

MapSVG < 8.6.12 - Authenticated (Contributor+) Arbitrary File Download

medium

The MapSVG plugin for WordPress is vulnerable to Path Traversal in all versions up to 8.6.12 (exclusive). This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS:
4.3
Affected:
up to 8.6.12
Fixed in:
8.6.12
Disclosed:
Jul 31, 2025

CVE-2025-54748 on NVD →

MapSVG [mapsvg] <= 8.5.32 (unfixed)

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG allows Upload a Web Shell to a Web Server. This issue affects MapSVG: from n/a through 8.5.32.

Affected:
up to 8.5.32
Fix:
No patched version reported
Disclosed:
Jun 17, 2025

CVE-2025-47559 on NVD →

MapSVG < 8.7.4 - Authenticated (Contributor+) Arbitrary File Upload

high

The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and excluding, 8.7.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make rem...

CVSS:
8.8
Affected:
up to 8.7.4
Fixed in:
8.7.4
Disclosed:
Jun 12, 2025

CVE-2025-47559 on NVD →

MapSVG < 8.6.13 - Authenticated (Contributor+) Privilege Esclation

high

The MapSVG plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and excluding, 8.6.13. This makes it possible for authenticated attackers, with Contributor-level access and above, to gain elevated access to the site.

CVSS:
8.8
Affected:
up to 8.6.13
Fixed in:
8.6.13
Disclosed:
Jun 9, 2025

CVE-2025-47561 on NVD →

MapSVG [mapsvg] <= 8.5.34 (unfixed)

unknown

[en] Incorrect Privilege Assignment vulnerability in PT Norther Lights Production MapSVG allows Privilege Escalation.This issue affects MapSVG: from n/a before 8.6.13.

Affected:
up to 8.5.34
Fix:
No patched version reported
Disclosed:
Jun 9, 2025

CVE-2025-47561 on NVD →

MapSVG [mapsvg] <= 8.5.31 (unfixed)

unknown

[en] Missing Authorization vulnerability in PT Norther Lights Production MapSVG allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MapSVG: from n/a before 8.6.13.

Affected:
up to 8.5.31
Fix:
No patched version reported
Disclosed:
May 23, 2025

CVE-2025-47558 on NVD →

MapSVG <= 8.6.13 - Missing Authorization

medium

The MapSVG plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and excluding, 8.6.13. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 8.6.13
Fixed in:
8.6.13
Disclosed:
May 22, 2025

CVE-2025-47558 on NVD →

MapSVG - All Kinds of Maps and Store Locator for WordPress <= 8.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 8.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web s...

CVSS:
6.4
Affected:
up to 8.6.4
Fix:
No patched version reported
Disclosed:
May 21, 2025

CVE-2024-9544 on NVD →

MapSVG <= 8.5.34 - Unauthenticated Arbitrary Shortcode Execution

medium

The The MapSVG plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.5.34. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to ex...

CVSS:
6.5
Affected:
up to 8.5.34
Fixed in:
8.6.11
Disclosed:
May 16, 2025

CVE-2025-47562 on NVD →

MapSVG <= 8.5.31 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.5.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wil...

CVSS:
6.4
Affected:
up to 8.5.31
Fixed in:
8.6.11
Disclosed:
May 16, 2025

CVE-2025-47557 on NVD →

MapSVG < 8.6.13 - Missing Authorization

medium

The MapSVG plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and excluding, 8.6.13. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 8.6.13
Fixed in:
8.6.13
Disclosed:
May 16, 2025

CVE-2025-47560 on NVD →

MapSVG [mapsvg] <= 8.5.31 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RomanCode MapSVG allows Stored XSS. This issue affects MapSVG: from n/a through 8.5.31.

Affected:
up to 8.5.31
Fix:
No patched version reported
Disclosed:
May 16, 2025

CVE-2025-47557 on NVD →

MapSVG [mapsvg] <= 8.5.32 (unfixed)

unknown

[en] Missing Authorization vulnerability in PT Norther Lights Production MapSVG allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MapSVG: from n/a before 8.6.13.

Affected:
up to 8.5.32
Fix:
No patched version reported
Disclosed:
May 16, 2025

CVE-2025-47560 on NVD →

MapSVG [mapsvg] <= 8.5.34 (unfixed)

unknown

[en] Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG allows Code Injection. This issue affects MapSVG: from n/a through 8.5.34.

Affected:
up to 8.5.34
Fix:
No patched version reported
Disclosed:
May 16, 2025

CVE-2025-47562 on NVD →

MapSVG [mapsvg] < 6.2.20

unknown

[en] The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.

Affected:
up to 6.2.20
Fixed in:
6.2.20
Disclosed:
May 9, 2022

CVE-2022-0592 on NVD →

MapSVG <= 6.2.19 - SQL Injection

high

The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.

CVSS:
7.3
Affected:
up to 6.2.20
Fixed in:
6.2.20
Disclosed:
Apr 18, 2022

CVE-2022-0592 on NVD →

MapSVG [mapsvg] <= 8.6.4 (unfixed)

unknown
Affected:
up to 8.6.4
Fix:
No patched version reported

CVE-2024-9544 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database