Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.2

CVE-2026-1771: MapSVG <= 8.14.0: Administrator Can Upload Any File

CVE-2026-1771 CVE-2026-1771
Summary

The MapSVG plugin for WordPress allows administrators to upload any file, potentially leading to malicious code being executed on the site. This is a serious issue because it could allow an attacker to take control of the site. To fix this, update the MapSVG plugin to version 8.14.1 or later.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
oyatek mapsvg – vector maps, image maps, google maps <= 8.14.0
Original title
The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all versions up to, and including, 8.14.0 This is due to an...
Original description
The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all versions up to, and including, 8.14.0 This is due to an incorrect conditional check that prevents file validation from taking place. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
mitre CVSS3.1 7.2
Vulnerability type
CWE-20 Improper Input Validation
Published: 21 Jul 2026 · Updated: 21 Jul 2026 · First seen: 21 Jul 2026