Skip to main content

MapSVG WordPress Plugin Arbitrary File Upload Allows Administrator-Level Remote Code Execution (CVE-2026-1771)

Scope: MapSVG WordPress Plugin Versions up to and Including 8.14.0

Severity: High

A high-severity arbitrary file upload vulnerability (CVSS 7.2) in the MapSVG WordPress plugin stems from an incorrect conditional check in the SVGFile constructor that causes file type validation to be skipped entirely despite the code appearing to include such a check. An attacker with administrator-level WordPress credentials can upload arbitrary file types including PHP web shells to the server, enabling persistent remote code execution, full server compromise, and lateral movement to other sites on the same hosting environment. While administrator credentials are required, this is a meaningful risk given that administrator accounts are frequently compromised through credential phishing, password reuse, or chaining with other privilege escalation vulnerabilities. Organizations must update MapSVG to version 8.14.1 or later immediately, and where patching is delayed, disable the SVG file upload functionality entirely via plugin settings.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.