Executive brief
The MapSVG plugin for WordPress, which is used to create interactive vector and Google maps, contains a security flaw that allows for unauthorized file uploads. An attacker with administrative access can bypass security checks to upload malicious files, such as web shells, to the server. This could lead to a complete takeover of the website and the underlying server infrastructure.
Technical details
The MapSVG plugin for WordPress suffers from an arbitrary file upload vulnerability within the SVGFile constructor. The root cause is an incorrect conditional check that inadvertently bypasses file type validation routines. This flaw allows authenticated attackers with Administrator-level privileges to upload arbitrary files, including PHP scripts, to the web server. Successful exploitation can lead to Remote Code Execution (RCE). The vulnerability is present in all versions up to 8.14.0 and was addressed in version 8.14.1.
Affected products
- oyatek MapSVG – Vector maps, Image maps, Google Maps up to, and including, 8.14.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory
References
- https://plugins.trac.wordpress.org/browser/mapsvg-lite-interactive-vector-maps/tags/8.9.1/php/Domain/File/FilesRepository.php
- https://plugins.trac.wordpress.org/browser/mapsvg-lite-interactive-vector-maps/tags/8.9.1/php/Domain/SVGFile/SVGFile.php
- https://plugins.trac.wordpress.org/browser/mapsvg-lite-interactive-vector-maps/tags/8.9.1/php/Router.php
- https://plugins.trac.wordpress.org/browser/mapsvg-lite-interactive-vector-maps/trunk/php/Domain/SVGFile/SVGFile.php
- https://plugins.trac.wordpress.org/changeset/3608308/mapsvg-lite-interactive-vector-maps/trunk/php/Domain/SVGFile/SVGFile.php
- https://plugins.trac.wordpress.org/changeset?old_path=%2Fmapsvg-lite-interactive-vector-maps/tags/8.14.0&new_path=%2Fmapsvg-lite-interactive-vector-maps/tags/8.14.1
- https://www.wordfence.com/threat-intel/vulnerabilities/id/c7f098b9-eca3-41c7-9c74-0f4b3f75c915?source=cve