MapSVG <= 8.14.0 - Unauthenticated SQL Injection
high
The MapSVG plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.14.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into alr...
- CVSS:
- 7.5
- Affected:
- up to 8.14.0
- Fixed in:
- 8.14.1
- Disclosed:
- Jul 23, 2026
CVE-2026-59526 on NVD →
MapSVG <= 8.14.0 - Authenticated (Contributor+) SQL Injection
medium
The MapSVG plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.14.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, t...
- CVSS:
- 6.5
- Affected:
- up to 8.14.0
- Fixed in:
- 8.14.1
- Disclosed:
- Jul 22, 2026
CVE-2026-65451 on NVD →
MapSVG [mapsvg] < 8.6.12
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RomanCode MapSVG mapsvg allows Path Traversal.This issue affects MapSVG: from n/a through < 8.6.12.
- Affected:
- up to 8.6.12
- Fixed in:
- 8.6.12
- Disclosed:
- Dec 18, 2025
CVE-2025-54748 on NVD →
MapSVG [mapsvg] < 8.7.4
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RomanCode MapSVG allows SQL Injection. This issue affects MapSVG: from n/a through n/a.
- Affected:
- up to 8.7.4
- Fixed in:
- 8.7.4
- Disclosed:
- Aug 14, 2025
CVE-2025-54669 on NVD →
MapSVG < 8.7.4 - Unauthenticated SQL Injection
high
The MapSVG plugin for WordPress is vulnerable to SQL Injection in versions up to 8.7.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing qu...
- CVSS:
- 7.5
- Affected:
- up to 8.7.4
- Fixed in:
- 8.7.4
- Disclosed:
- Aug 8, 2025
CVE-2025-54669 on NVD →
MapSVG < 8.6.12 - Authenticated (Contributor+) Arbitrary File Download
medium
The MapSVG plugin for WordPress is vulnerable to Path Traversal in all versions up to 8.6.12 (exclusive). This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 4.3
- Affected:
- up to 8.6.12
- Fixed in:
- 8.6.12
- Disclosed:
- Jul 31, 2025
CVE-2025-54748 on NVD →
MapSVG [mapsvg] <= 8.5.32 (unfixed)
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG allows Upload a Web Shell to a Web Server. This issue affects MapSVG: from n/a through 8.5.32.
- Affected:
- up to 8.5.32
- Fix:
- No patched version reported
- Disclosed:
- Jun 17, 2025
CVE-2025-47559 on NVD →
MapSVG < 8.7.4 - Authenticated (Contributor+) Arbitrary File Upload
high
The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and excluding, 8.7.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make rem...
- CVSS:
- 8.8
- Affected:
- up to 8.7.4
- Fixed in:
- 8.7.4
- Disclosed:
- Jun 12, 2025
CVE-2025-47559 on NVD →
MapSVG < 8.6.13 - Authenticated (Contributor+) Privilege Esclation
high
The MapSVG plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and excluding, 8.6.13. This makes it possible for authenticated attackers, with Contributor-level access and above, to gain elevated access to the site.
- CVSS:
- 8.8
- Affected:
- up to 8.6.13
- Fixed in:
- 8.6.13
- Disclosed:
- Jun 9, 2025
CVE-2025-47561 on NVD →
MapSVG [mapsvg] <= 8.5.34 (unfixed)
unknown
[en] Incorrect Privilege Assignment vulnerability in PT Norther Lights Production MapSVG allows Privilege Escalation.This issue affects MapSVG: from n/a before 8.6.13.
- Affected:
- up to 8.5.34
- Fix:
- No patched version reported
- Disclosed:
- Jun 9, 2025
CVE-2025-47561 on NVD →
MapSVG [mapsvg] <= 8.5.31 (unfixed)
unknown
[en] Missing Authorization vulnerability in PT Norther Lights Production MapSVG allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MapSVG: from n/a before 8.6.13.
- Affected:
- up to 8.5.31
- Fix:
- No patched version reported
- Disclosed:
- May 23, 2025
CVE-2025-47558 on NVD →
MapSVG <= 8.6.13 - Missing Authorization
medium
The MapSVG plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and excluding, 8.6.13. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 8.6.13
- Fixed in:
- 8.6.13
- Disclosed:
- May 22, 2025
CVE-2025-47558 on NVD →
MapSVG - All Kinds of Maps and Store Locator for WordPress <= 8.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 8.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web s...
- CVSS:
- 6.4
- Affected:
- up to 8.6.4
- Fix:
- No patched version reported
- Disclosed:
- May 21, 2025
CVE-2024-9544 on NVD →
MapSVG <= 8.5.34 - Unauthenticated Arbitrary Shortcode Execution
medium
The The MapSVG plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.5.34. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to ex...
- CVSS:
- 6.5
- Affected:
- up to 8.5.34
- Fixed in:
- 8.6.11
- Disclosed:
- May 16, 2025
CVE-2025-47562 on NVD →
MapSVG <= 8.5.31 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.5.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wil...
- CVSS:
- 6.4
- Affected:
- up to 8.5.31
- Fixed in:
- 8.6.11
- Disclosed:
- May 16, 2025
CVE-2025-47557 on NVD →
MapSVG < 8.6.13 - Missing Authorization
medium
The MapSVG plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and excluding, 8.6.13. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 8.6.13
- Fixed in:
- 8.6.13
- Disclosed:
- May 16, 2025
CVE-2025-47560 on NVD →
MapSVG [mapsvg] <= 8.5.31 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RomanCode MapSVG allows Stored XSS. This issue affects MapSVG: from n/a through 8.5.31.
- Affected:
- up to 8.5.31
- Fix:
- No patched version reported
- Disclosed:
- May 16, 2025
CVE-2025-47557 on NVD →
MapSVG [mapsvg] <= 8.5.32 (unfixed)
unknown
[en] Missing Authorization vulnerability in PT Norther Lights Production MapSVG allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MapSVG: from n/a before 8.6.13.
- Affected:
- up to 8.5.32
- Fix:
- No patched version reported
- Disclosed:
- May 16, 2025
CVE-2025-47560 on NVD →
MapSVG [mapsvg] <= 8.5.34 (unfixed)
unknown
[en] Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG allows Code Injection. This issue affects MapSVG: from n/a through 8.5.34.
- Affected:
- up to 8.5.34
- Fix:
- No patched version reported
- Disclosed:
- May 16, 2025
CVE-2025-47562 on NVD →
MapSVG [mapsvg] < 6.2.20
unknown
[en] The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.
- Affected:
- up to 6.2.20
- Fixed in:
- 6.2.20
- Disclosed:
- May 9, 2022
CVE-2022-0592 on NVD →
MapSVG <= 6.2.19 - SQL Injection
high
The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.
- CVSS:
- 7.3
- Affected:
- up to 6.2.20
- Fixed in:
- 6.2.20
- Disclosed:
- Apr 18, 2022
CVE-2022-0592 on NVD →
MapSVG [mapsvg] <= 8.6.4 (unfixed)
unknown
- Affected:
- up to 8.6.4
- Fix:
- No patched version reported
CVE-2024-9544 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database