Description
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
Published: 2026-07-23
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a contributor‑driven SQL Injection flaw present in MapSVG plugin versions 8.14.0 and earlier. Attackers can submit crafted input that is unsafely integrated into database queries, enabling them to read, modify, or delete database contents. This compromises the confidentiality and integrity of the data stored by affected WordPress sites, and could provide a foothold for further exploitation if administrative privileges are gained.

Affected Systems

The flaw affects the RomanCode MapSVG WordPress plugin for all releases up to and including version 8.14.0. WordPress sites that have installed any of these versions are vulnerable, regardless of the underlying WordPress core version.

Risk and Exploitability

The CVSS v3 score of 8.5 classifies this as a high‑severity issue. The EPSS figure of less than 1 % indicates that exploitation attempts are currently infrequent, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a web request that includes malicious SQL payloads; based on the description it is inferred that the vulnerability can be triggered from the front‑end or back‑end interfaces of the plugin.

Generated by OpenCVE AI on August 3, 2026 at 22:12 UTC.

Remediation

Vendor Solution

Update the WordPress MapSVG Plugin to the latest available version (at least 8.14.1).


OpenCVE Recommended Actions

  • Update the WordPress MapSVG plugin to version 8.14.1 or newer, as advised by the vendor.
  • If an update cannot be applied immediately, deactivate or uninstall the plugin to eliminate the attack surface.
  • Limit database permissions by configuring the WordPress database user with only the minimum privileges required for normal operation to reduce potential damage if the vulnerability is exploited.

Generated by OpenCVE AI on August 3, 2026 at 22:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Romancode
Romancode mapsvg
Wordpress
Wordpress wordpress
Vendors & Products Romancode
Romancode mapsvg
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Contributor SQL Injection in MapSVG <= 8.14.0 versions.
Title WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Romancode Mapsvg
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T13:29:51.219Z

Reserved: 2026-07-22T08:53:04.434Z

Link: CVE-2026-65450

cve-icon Vulnrichment

Updated: 2026-07-23T13:29:45.280Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:37.350

Modified: 2026-07-23T14:17:47.530

Link: CVE-2026-65450

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:15:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')