An authenticated attacker with Administrator-level access can exploit CVE-2026-1771 in the MapSVG WordPress plugin, affecting versions up to 8.14.0, due to missing file type validation, enabling arbitrary file uploads and potentially leading to remote code execution on the server.
MapSVG – Vector maps, Image maps, Google Maps <= 8.14.0
wordpress
plugin
arbitrary-file-upload
rce
web-application
1r
3t
1c