Executive brief
MapSVG is a popular WordPress plugin used to create interactive vector maps on websites. An unauthenticated Server Side Request Forgery (SSRF) vulnerability allows attackers to make the web server connect to internal systems and services, potentially leaking sensitive data or accessing systems behind the firewall without requiring any login credentials.
Technical details
This is a Server Side Request Forgery (SSRF) vulnerability in the MapSVG WordPress plugin versions up to 8.15.0. The vulnerability is unauthenticated, meaning no user login is required to exploit it. An attacker can craft malicious requests that cause the server to make connections to internal systems or services, bypassing network-based access controls and potentially exposing sensitive data or internal infrastructure. The vulnerability has been patched in version 8.16.0 and later.
Affected products
- PT Norther Lights Production MapSVG <= 8.15.0
Timeline
- 2026-08-31: disclosed: Vulnerability published on NVD and Patchstack
- 2026-08-31: patched: Patched in version 8.16.0
- 2026-07-21: other: Reported by Adam Kahlon (Adkali)