Junglewise Threat Intelligence

CVE-2026-65455: MapSVG arbitrary file upload in WordPress plugin

CVE-2026-65455 · Severity: critical · CVSS 9.1 · Published 2026-07-23

Technologies: MapSVG.

Executive brief

MapSVG is a WordPress plugin used to create interactive vector maps. A security vulnerability allows an administrative user to upload malicious files, such as web shells, directly to the server. This could lead to a complete takeover of the website and the underlying server infrastructure.

Technical details

The MapSVG plugin for WordPress (versions <= 8.14.0) contains an unrestricted file upload vulnerability (CWE-434). The flaw allows an authenticated user with Administrator privileges to upload dangerous file types, such as PHP scripts, to the web server. Because the plugin fails to properly validate file extensions or content, an attacker can achieve remote code execution (RCE) and potentially escape the WordPress environment to the host system. The vulnerability is addressed in version 8.14.1.

Affected products

  • MapSVG MapSVG <= 8.14.0

Timeline

  • 2026-04-29: other: Reported by Securepeak Research Team
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: NVD publication date
  • 2026-07-23: patched: Version 8.14.1 released to address the issue

References