CVE-2026-59526
MapSVG plugin versions up to 8.14.0 contain an unauthenticated SQL injection flaw. The vulnerability can be exploited remotely without any user interaction, allowing attackers to read or alter database contents.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
WordPress site owners using the MapSVG plugin, specifically versions 8.14.0 and earlier.
Real-world impact
An attacker could extract sensitive data such as user credentials, site content, or configuration settings, or modify database records, potentially leading to defacement, data loss, or further compromise of the site.
Why this severity
The CVSS score of 9.3 reflects a network‑based attack that requires no authentication and can fully compromise confidentiality, while integrity and availability impacts are lower. The high score indicates the vulnerability is both easy to exploit and potentially damaging.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources