Executive brief
MapSVG is a WordPress plugin used to create interactive vector maps. A critical security flaw allows unauthorized individuals to send malicious commands to the website's database without needing a password. This could lead to the theft of sensitive customer data, unauthorized access to site information, or disruption of website operations.
Technical details
An unauthenticated SQL injection vulnerability exists in the MapSVG WordPress plugin (versions 8.14.0 and below). The flaw is classified as CWE-89, resulting from improper neutralization of special elements used in an SQL command. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the affected WordPress site, allowing them to interact directly with the backend database. This can lead to full data exfiltration or unauthorized modification of database records. The issue is resolved in version 8.14.1.
Affected products
- RomanCode / PT Norther Lights Production MapSVG <= 8.14.0
Timeline
- 2026-01-23: disclosed: Reported by Trương Hữu Phúc via Patchstack
- 2026-07-23: advisory: Patchstack published advisory details
- 2026-07-27: patched: NVD publication and confirmation of fix in 8.14.1