Description
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
Published: 2026-07-23
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

MapSVG plugin versions up to 8.14.0 allow an authenticated administrative user to upload files without type, including executable scripts, which can be run on the web server. If an attacker can place a malicious script on the server, they can gain remote code execution, compromising the entire WordPress installation and potentially the underlying operating system. The weakness corresponds Upload of File with Dangerous Type.

Affected Systems

WordPress sites that use the MapSVG plugin in versions 8.14.0 or earlier are affected. The issue is specific to the MapSVG plugin component, not to WordPress core or other plugins.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that the probability of exploitation is low at the moment, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the flaw requires administrative authentication, an attacker who compromises or hijacks an admin account, or who has local access to the site, can exploit the upload shortcut. Once a malicious file is successfully uploaded, it can be executed, reading, modifying, or deleting site data and possibly backdooring the server.

Generated by OpenCVE AI on August 3, 2026 at 22:10 UTC.

Remediation

Vendor Solution

Update the WordPress MapSVG Plugin to the latest available version (at least 8.14.1).


OpenCVE Recommended Actions

  • Update the WordPress MapSVG Plugin to version 8.14.1 or newer to remove the upload flaw
  • Configure the plugin to reject or quarantine non‑image file uploads, or disable the upload feature if not needed
  • Implement a web application firewall or file‑type validation layer to block dangerous file uploads and monitor upload activity for suspicious patterns

Generated by OpenCVE AI on August 3, 2026 at 22:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Mapsvg
Mapsvg mapsvg
Wordpress
Wordpress wordpress
Vendors & Products Mapsvg
Mapsvg mapsvg
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
Title WordPress MapSVG plugin <= 8.14.0 - Arbitrary File Upload vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Mapsvg Mapsvg
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T14:52:08.214Z

Reserved: 2026-07-22T08:53:17.417Z

Link: CVE-2026-65455

cve-icon Vulnrichment

Updated: 2026-07-23T14:07:54.074Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:37.950

Modified: 2026-07-23T15:17:56.303

Link: CVE-2026-65455

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:15:04Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type