Extension WordPress
Vulnérabilités MapSVG
Cette page rassemble les failles publiées pour MapSVG, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de MapSVG
10 fiches
MapSVG < 8.7.4 – Unauthenticated SQL Injection
The MapSVG plugin for WordPress is vulnerable to SQL Injection in versions up to 8.7.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…
[*, 8.7.4)
8.7.4
08/08/2025
MapSVG < 8.6.12 – Authenticated (Contributor+) Arbitrary File Download
The MapSVG plugin for WordPress is vulnerable to Path Traversal in all versions up to 8.6.12 (exclusive). This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the…
[*, 8.6.12)
8.6.12
31/07/2025
MapSVG < 8.7.4 – Authenticated (Contributor+) Arbitrary File Upload
The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and excluding, 8.7.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
[*, 8.7.4)
8.7.4
12/06/2025
MapSVG < 8.6.13 – Authenticated (Contributor+) Privilege Esclation
The MapSVG plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and excluding, 8.6.13. This makes it possible for authenticated attackers, with Contributor-level access and above, to gain elevated access to the site.
[*, 8.6.13)
8.6.13
09/06/2025
MapSVG <= 8.6.13 – Missing Authorization
The MapSVG plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and excluding, 8.6.13. This makes it possible for unauthenticated attackers to perform an unauthorized…
[*, 8.6.13)
8.6.13
22/05/2025
MapSVG – All Kinds of Maps and Store Locator for WordPress <= 8.6.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 8.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-8.6.4
Non indiqué
21/05/2025
MapSVG < 8.6.13 – Missing Authorization
The MapSVG plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and excluding, 8.6.13. This makes it possible for authenticated attackers, with Contributor-level access and…
[*, 8.6.13)
8.6.13
16/05/2025
MapSVG <= 8.5.31 – Authenticated (Contributor+) Stored Cross-Site Scripting
The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.5.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-8.5.31
8.6.11
16/05/2025
MapSVG <= 8.5.34 – Unauthenticated Arbitrary Shortcode Execution
The The MapSVG plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.5.34. This is due to the software allowing users to execute an action that does not properly validate a…
*-8.5.34
8.6.11
16/05/2025
MapSVG <= 6.2.19 – SQL Injection
The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.
[*, 6.2.20)
6.2.20
18/04/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.