Cross Site Scripting Vulnerability in MapSVG Plugin from WordPress
CVE-2026-65449

6.5MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-65449?

A security vulnerability exists in the MapSVG plugin for WordPress, specifically in versions up to 8.14.0. This vulnerability allows attackers to execute arbitrary JavaScript code in the context of a user's session through Cross Site Scripting (XSS). By exploiting this flaw, an attacker may gain the ability to manipulate web content viewed by clients, potentially leading to data theft or unauthorized actions on the website. Website owners using affected versions should take immediate measures to apply security updates and safeguard their users.

Affected Version(s)

MapSVG <= 8.14.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

johska | Patchstack Bug Bounty Program
.