CVE-2026-82852: WordPress MapSVG plugin <= 8.15.0 - Server Side Request Forgery (SSRF) vulnerability
Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress MapSVG pluginto a version that resolves this vulnerability.Fixed in 8.15.0 - Compensating control
Restrict network egress from the WordPress server so it cannot reach internal services/endpoints that could be targeted by SSRF via the MapSVG plugin.
Event History
Frequently Asked Questions
Which installations are affected?
WordPress sites using the MapSVG plugin version 8.15.0 or earlier are affected according to the available vulnerability data.
Does exploitation require an authenticated WordPress account or user interaction?
No. The vulnerability is described as unauthenticated, and the vector indicates no privileges or user interaction are required.
What could an attacker gain through successful exploitation?
The reported impact includes low confidentiality and low integrity impact, with no availability impact indicated. Exploitation may allow an attacker to cause the server to make requests to attacker-selected destinations.