Executive brief
MapSVG is a WordPress plugin used to create interactive maps and floor plans. A security flaw in versions 8.14.0 and earlier allows a user with 'Contributor' level access to run unauthorized database commands. This could lead to the theft of sensitive information stored in the website's database or potential disruption of site operations.
Technical details
A SQL injection vulnerability exists in the RomanCode MapSVG plugin for WordPress (versions <= 8.14.0) due to improper neutralization of special elements used in SQL commands (CWE-89). The vulnerability is accessible to authenticated users with 'Contributor' privileges or higher. An attacker can exploit this flaw by sending specially crafted network requests to the WordPress backend, allowing for unauthorized database queries. This can result in high confidentiality impact as attackers may extract sensitive data from the database. The issue is resolved in version 8.14.1.
Affected products
- RomanCode MapSVG <= 8.14.0
Timeline
- 2026-01-23: other: Reported by Trương Hữu Phúc
- 2026-07-22: advisory: Patchstack advisory published
- 2026-07-23: disclosed: NVD publication date
- 2026-07-23: patched: Version 8.14.1 released to address the vulnerability