CVE-2026-59527
This vulnerability allows attackers to inject SQL commands into the MapSVG plugin without authentication, potentially exposing sensitive data. It can be exploited remotely by anyone who can access the affected WordPress site.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
MapSVG plugin for WordPress, versions 8.14.0 and earlier, used by website administrators who manage interactive maps.
Real-world impact
An attacker could read or modify the database, leading to data theft, site defacement, or further compromise of the WordPress installation.
Why this severity
The CVSS score of 9.3 reflects a network‑based attack that requires no user interaction and can give attackers full control over the database. The high impact on confidentiality and the ease of exploitation make it critical.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources