Junglewise Threat Intelligence

CVE-2026-1771: MapSVG WordPress plugin arbitrary file upload in SVGFile constructor

CVE-2026-1771 · Severity: high · CVSS 7.2 · Published 2026-07-21

Technologies: Oyatek MapSVG. Vendors: Oyatek.

Executive brief

The MapSVG plugin for WordPress, which is used to create interactive vector and Google maps, contains a security flaw that allows for unauthorized file uploads. An attacker with administrative access can bypass security checks to upload malicious files, such as web shells, to the server. This could lead to a complete takeover of the website and the underlying server infrastructure.

Technical details

The MapSVG plugin for WordPress suffers from an arbitrary file upload vulnerability within the SVGFile constructor. The root cause is an incorrect conditional check that inadvertently bypasses file type validation routines. This flaw allows authenticated attackers with Administrator-level privileges to upload arbitrary files, including PHP scripts, to the web server. Successful exploitation can lead to Remote Code Execution (RCE). The vulnerability is present in all versions up to 8.14.0 and was addressed in version 8.14.1.

Affected products

  • oyatek MapSVG – Vector maps, Image maps, Google Maps up to, and including, 8.14.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References