Executive brief
MapSVG is a WordPress plugin used to create interactive vector maps. A security vulnerability allows users with 'Contributor' level access to perform unauthorized database queries. This could lead to the exposure of sensitive site information or disruption of database operations.
Technical details
A SQL injection vulnerability exists in the MapSVG plugin for WordPress (versions <= 8.14.0) due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is accessible to authenticated users with 'Contributor' privileges or higher. An attacker can exploit this by sending specially crafted network requests to interact directly with the underlying database. This can result in unauthorized data retrieval or limited impact on database availability. The issue is addressed in version 8.14.1.
Affected products
- RomanCode MapSVG <= 8.14.0
Timeline
- 2026-01-23: other: Vulnerability reported by researcher
- 2026-07-22: advisory: Patchstack advisory published
- 2026-07-23: disclosed: CVE published to NVD