PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 9, 2026

WordPress Mapplic <= 6.1 / Mapplic Lite <= 1.0 - Authenticated Stored XSS via SVG File Upload

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3.2k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2012-10018
8.3
CVSShigh
Exploitable remotely over the internet · no authentication required.

The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes it possible for attackers to forgery requests coming from a vulnerable site's server and ultimately perform an XSS attack if requesting an SVG file.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Mapplic Liteby sekler
AFFECTED< 1.0.1SAFE ✓≥ 1.0.1
Mapplic - Custom Interactive Map WordPress Pluginby sekler
AFFECTED< 6.2SAFE ✓≥ 6.2
mapplicby mapplic
AFFECTED< 6.2SAFE ✓≥ 6.2
mapplic_liteby mapplic
AFFECTED< 1.0.1SAFE ✓≥ 1.0.1
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

WordPress Mapplic <= 6.1 / Mapplic Lite <= 1.0 - Authenticated Stored XSS via SVG File Upload CVE-2012-10018 Scanner | S4E