Stored Cross-Site Scripting Vulnerability in MapSVG Plugin for WordPress
CVE-2025-9205
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 July 2026
What is CVE-2025-9205?
The MapSVG plugin for WordPress contains a vulnerability that allows authenticated attackers with contributor-level access or higher to exploit the insufficient input sanitization and output escaping of user-supplied attributes within map options. This flaw enables the injection of arbitrary web scripts into pages, which can be executed when users visit the compromised pages, posing a significant risk to website security and user trust.
Affected Version(s)
MapSVG β Vector maps, Image maps, Google Maps 0 <= 8.14.0