Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RomanCode MapSVG mapsvg allows Stored XSS.This issue affects MapSVG: from n/a through <= 8.5.31.
Published: 2025-05-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MapSVG plugin (RomanCode) contains a stored cross‑site scripting flaw that allows an attacker to embed malicious JavaScript in site content. When a user views the affected map or page, the injected script executes in the victim’s browser, potentially yielding session hijacking, phishing, or defacement. This weakness is classified as CWE‑79 and represents a moderate‑to‑high risk to confidentiality, integrity, and availability of site data. The vulnerability is not limited to a single user—it can affect any visitor accessing the compromised content.

Affected Systems

WordPress sites running the MapSVG plugin version 8.5.31 or earlier are vulnerable. This applies to all installations of the plugin distributed by RomanCode, regardless of the WordPress theme or other plugins in use. No specific operating system or WordPress core version is required for exploitation; the flaw resides solely within the plugin’s content handling.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests low exploitation probability at the time of analysis. The vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the likely attack vector is the plugin’s web‑based map editor or content management interface where user input is stored without proper neutralization. An attacker would need the ability to create or edit a map; once the malicious script is stored, any subsequent page view triggers the code in the victim’s context. The impact is widespread to all site visitors until the flaw is patched or mitigated.

Generated by OpenCVE AI on April 30, 2026 at 12:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the MapSVG plugin to a version newer than 8.5.31 as soon as an official patch is released.
  • If a newer version is not available, disable or uninstall the MapSVG plugin to eliminate the attack surface.
  • Review and cleanse any existing map or content objects that may contain injected scripts; consider recreating maps with safe data or removing potentially compromised content altogether.

Generated by OpenCVE AI on April 30, 2026 at 12:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-15502 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RomanCode MapSVG allows Stored XSS. This issue affects MapSVG: from n/a through 8.5.31.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RomanCode MapSVG allows Stored XSS. This issue affects MapSVG: from n/a through 8.5.31. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RomanCode MapSVG mapsvg allows Stored XSS.This issue affects MapSVG: from n/a through <= 8.5.31.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 16 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 May 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RomanCode MapSVG allows Stored XSS. This issue affects MapSVG: from n/a through 8.5.31.
Title WordPress MapSVG plugin <= 8.5.31 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:44.869Z

Reserved: 2025-05-07T09:40:07.680Z

Link: CVE-2025-47557

cve-icon Vulnrichment

Updated: 2025-05-16T18:10:54.231Z

cve-icon NVD

Status : Deferred

Published: 2025-05-16T16:15:42.180

Modified: 2026-04-23T15:30:28.983

Link: CVE-2025-47557

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T13:00:13Z

Weaknesses