
MapSVG – Vector maps, Image maps, Google Maps Security & Risk Analysis
wordpress.org/plugins/mapsvg-lite-interactive-vector-mapsCreate interactive vector maps, floor plans, and image maps. Support for Google Maps integration, custom markers, tooltips, and popups.
Is MapSVG – Vector maps, Image maps, Google Maps Safe to Use in 2026?
Generally Safe
Score 89/100MapSVG – Vector maps, Image maps, Google Maps has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "mapsvg-lite-interactive-vector-maps" v8.10.1 presents a mixed security posture. While it demonstrates good practices in output escaping and a significant portion of SQL queries utilizing prepared statements, several concerning factors are evident. The static analysis highlights a notable attack surface with one unprotected REST API route, indicating a potential entry point for unauthenticated attackers. Furthermore, the presence of a dangerous function like `unserialize` warrants careful scrutiny, as improper handling of serialized data can lead to remote code execution vulnerabilities. The taint analysis, though limited in scope, reveals flows with unsanitized paths, which could be exploited if not thoroughly addressed. The vulnerability history is particularly concerning, with a significant number of past CVEs including high-severity issues like Unrestricted File Upload, Cross-Site Scripting, Code Injection, Missing Authorization, and CSRF. While there are currently no unpatched CVEs, the recurring nature of these vulnerability types suggests potential systemic weaknesses in input validation and authorization mechanisms that could resurface.
Key Concerns
- Unprotected REST API route
- Dangerous function: unserialize
- Flows with unsanitized paths
- History of High severity CVEs (2)
- History of Medium severity CVEs (5)
- Lack of Nonce checks
MapSVG – Vector maps, Image maps, Google Maps Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
MapSVG <= 8.7.3 - Authenticated (Contributor+) Arbitrary File Upload
MapSVG <= 8.7.23 - Authenticated (Contributor+) Stored Cross-Site Scripting
MapSVG Lite <= 8.6.9 - Unauthenticated Arbitrary Shortcode Execution
MapSVG Lite <= 8.6.4 - Authenticated (Contributor+) Arbitrary File Upload
MapSVG Lite <= 8.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
MapSVG Lite <= 8.6.4 - Missing Authorization
MapSVG Lite < 3.3.0 - Cross-Site Request Forgery
MapSVG – Vector maps, Image maps, Google Maps Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
MapSVG – Vector maps, Image maps, Google Maps Attack Surface
REST API Routes 1
Shortcodes 1
WordPress Hooks 35
Maintenance & Trust
MapSVG – Vector maps, Image maps, Google Maps Maintenance & Trust
Maintenance Signals
Community Trust
MapSVG – Vector maps, Image maps, Google Maps Alternatives
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
wp-google-map-plugin
WordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.
WP Store Locator
wp-store-locator
An easy to use location management system that enables users to search for nearby physical stores.
MapPress Maps for WordPress
mappress-google-maps-for-wordpress
MapPress is the easiest way to add unlimited interactive Google and Leaflet maps to WordPress.
Store Locator WordPress
agile-store-locator
Agile Store Locator is a premium store finder plugin designed to offer you immediate access to all the best stores in your local area.
Maps Plugin using Google Maps for WordPress – WP Google Map
gmap-embed
Google Map plugin for WordPress is very Simple, light-weight and Easy to use Google Custom Map with markers in Posts, Pages, Sidebar as shortcode.
MapSVG – Vector maps, Image maps, Google Maps Developer Profile
1 plugin · 1K total installs
How We Detect MapSVG – Vector maps, Image maps, Google Maps
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mapsvg-lite-interactive-vector-maps/css/style.css/wp-content/plugins/mapsvg-lite-interactive-vector-maps/css/admin.css/wp-content/plugins/mapsvg-lite-interactive-vector-maps/js/script.js/wp-content/plugins/mapsvg-lite-interactive-vector-maps/js/admin.js/wp-content/plugins/mapsvg-lite-interactive-vector-maps/js/script.js/wp-content/plugins/mapsvg-lite-interactive-vector-maps/js/admin.jsmapsvg-lite-interactive-vector-maps/css/style.css?ver=mapsvg-lite-interactive-vector-maps/css/admin.css?ver=mapsvg-lite-interactive-vector-maps/js/script.js?ver=mapsvg-lite-interactive-vector-maps/js/admin.js?ver=HTML / DOM Fingerprints
mapsvg-mapmapsvg-layers-listmapsvg-layermapsvg-region<!-- MapSVG Lite Admin Page --><!-- MapSVG plugin -->data-mapsvg-containerMapSVGAdmin/wp-json/mapsvg/v1/maps[mapsvg]