Executive brief
MapSVG is a WordPress plugin used to create interactive vector maps. A security vulnerability in versions 8.14.0 and earlier allows users with 'Contributor' level access to inject malicious scripts into the website. If an administrator or another visitor views the affected content, these scripts could be used to redirect users to malicious sites, display unauthorized advertisements, or perform actions on behalf of the victim.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in the MapSVG plugin for WordPress (versions up to and including 8.14.0). The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with Contributor-level privileges can inject arbitrary JavaScript into map-related data. The vulnerability requires a victim (such as a site administrator) to interact with the affected page or perform a specific action for the script to execute in their browser context. This can lead to session hijacking or unauthorized site modifications. The issue is resolved in version 8.14.1.
Affected products
- RomanCode MapSVG <= 8.14.0
Timeline
- 2026-01-15: other: Reported by researcher johska
- 2026-07-22: advisory: Patchstack advisory published
- 2026-07-23: disclosed: NVD publication date