What is CVE-2025-9205?
This vulnerability affects the MapSVG plugin for WordPress in all versions up to 8.14.0. Due to insufficient input sanitization and output escaping in map options, authenticated attackers can perform Stored XSS attacks. Update the plugin to the latest version.
Azərbaycanca: Bu boşluq WordPress-in MapSVG plaginin 8.14.0 daxil olmaqla bütün versiyalarını təsir edir. Xəritə seçimlərində kifayət qədər input sanitization və output escaping olmaması səbəbindən autentifikasiya olunmuş hücumçular Stored XSS həyata keçirə bilər. Plaginin ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the MapSVG plugin are affected by the CVE-2025-9205 vulnerability?
This vulnerability affects all versions of the MapSVG plugin up to and including version 8.14.0.
What action is recommended to mitigate the vulnerability?
Updating the plugin to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.