Cross Site Scripting Vulnerability in MapSVG Plugin from WordPress
CVE-2026-65449
6.5MEDIUM
What is CVE-2026-65449?
A security vulnerability exists in the MapSVG plugin for WordPress, specifically in versions up to 8.14.0. This vulnerability allows attackers to execute arbitrary JavaScript code in the context of a user's session through Cross Site Scripting (XSS). By exploiting this flaw, an attacker may gain the ability to manipulate web content viewed by clients, potentially leading to data theft or unauthorized actions on the website. Website owners using affected versions should take immediate measures to apply security updates and safeguard their users.
Affected Version(s)
MapSVG <= 8.14.0