The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.0. This is due to insufficient input sanitization and output escaping on user supplied attributes within the map options. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Security readout for executives and security teams
Plain-English summary
MapSVG Lite for WordPress versions through 8.14.0 can let a logged-in Contributor or more privileged user store malicious script in map settings. The script may run when someone views the affected page, potentially exposing browser-accessible information or allowing actions under the viewer’s session. Anonymous exploitation is not supported by the supplied evidence.
Executive priority
Treat this as a scheduled but prompt remediation item. Prioritize internet-facing sites with many contributors, sensitive administrator sessions, or signs of account compromise. Emergency response is not supported solely by the supplied evidence, but delaying remediation preserves a useful path for authenticated attackers.
Technical view
CVE-2025-9205 is stored cross-site scripting caused by insufficient sanitization and output escaping of user-controlled map-option attributes. It is remotely reachable but requires an authenticated Contributor-level account or higher. The CVSS 3.1 score is 6.4, with possible low confidentiality and integrity impact across a security boundary, but no stated availability impact.
Likely exposure
Exposure is likely limited to WordPress sites running MapSVG Lite 8.14.0 or earlier where untrusted or compromised users have Contributor-level access. Risk increases when affected pages are visited by administrators. The structured affected-product entry is inconsistent, listing version “0” and defaulting to unaffected, so confirm installed versions manually.
Exploitation context
The supplied sources do not establish active exploitation, and the CVE is not identified as a CISA KEV entry in the bundle. Exploitation requires authenticated content access, reducing broad internet-scale risk. Compromised Contributor accounts, weak account controls, or intentionally untrusted contributors remain credible entry points.
Researcher notes
CWE-79 and the CVSS vector support authenticated stored XSS with changed scope. The bundle links relevant plugin administration code and a WordPress changeset, but does not explicitly identify a fixed version or confirm exploitation. The structured affected-version data conflicts with the narrative range; validate against current vendor guidance before closing findings.
Mitigation direction
Inventory WordPress sites for MapSVG Lite and identify installations at version 8.14.0 or earlier.
Check current vendor guidance and install the vendor-confirmed fixed release when available.
Temporarily restrict Contributor access to map editing on affected sites.
Review Contributor and higher-privileged accounts; remove unnecessary access and secure suspected compromises.
Apply compensating content restrictions if immediate updating is unavailable.
Validation and detection
Confirm the installed MapSVG Lite version on every WordPress instance.
Verify whether Contributor-level users can create or modify affected map content.
Review recently changed map options and associated pages for unexpected script behavior.
Test affected pages safely using a non-privileged account in an isolated environment.
After remediation, confirm untrusted attributes are rejected or safely encoded when rendered.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-79 · source CWE mapping
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.