Junglewise Threat Intelligence

CVE-2026-59526: RomanCode MapSVG unauthenticated SQL injection

CVE-2026-59526 · Severity: critical · CVSS 9.3 · Published 2026-07-23

Technologies: RomanCode / PT Norther Lights Production MapSVG.

Executive brief

MapSVG, a WordPress plugin used for creating interactive maps, contains a critical security flaw that allows unauthorized individuals to interact with the website's database. An attacker could exploit this to steal sensitive information, such as user data or configuration details, without needing any login credentials. This type of vulnerability is frequently targeted in automated mass-exploitation campaigns against websites.

Technical details

A SQL injection vulnerability exists in the MapSVG WordPress plugin (versions <= 8.14.0) due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is exploitable by unauthenticated remote attackers over the network with low attack complexity. Because the vulnerability does not require user interaction or privileges, it poses a high risk of automated exploitation. Successful exploitation allows an attacker to execute arbitrary SQL queries, potentially leading to full data exfiltration from the WordPress database. The issue is resolved in version 8.14.1.

Affected products

  • RomanCode / PT Norther Lights Production MapSVG <= 8.14.0

Timeline

  • 2026-01-23: other: Reported by Trương Hữu Phúc
  • 2026-07-23: disclosed: Vulnerability published by Patchstack
  • 2026-07-23: patched: Version 8.14.1 released to address the issue

References