Junglewise Threat Intelligence

CVE-2020-37242: Supsystic Ultimate Maps SQL injection in sidx parameter

CVE-2020-37242 · Severity: high · CVSS 8.2 · Published 2026-05-16

Vendors: Supsystic.

Executive brief

Supsystic Ultimate Maps, a WordPress plugin used to create interactive maps, contains a security flaw that allows unauthorized individuals to access the website's database. By sending specially crafted web requests, an attacker can bypass security controls to steal sensitive information, such as user credentials or site configuration data. This could lead to a full compromise of the website or the exposure of private customer information.

Technical details

An SQL injection vulnerability exists in the Supsystic Ultimate Maps plugin for WordPress (version 1.1.12 and earlier) due to improper sanitization of the 'sidx' GET parameter within the 'getListForTbl' action. This flaw allows unauthenticated remote attackers to perform boolean-based blind or time-based blind SQL injection attacks. By exploiting this vulnerability, an attacker can execute arbitrary SQL queries to extract sensitive information from the WordPress database. The issue was reportedly fixed around December 9, 2020, following coordination with the WordPress Plugin Security team.

Affected products

  • Supsystic Ultimate Maps <= 1.1.12

Timeline

  • 2020-07-24: disclosed: Vulnerability discovered and vendor notified by Erik David Martin
  • 2020-12-09: patched: Vulnerability fixed following contact with WordPress Plugin Security team
  • 2021-02-08: other: Exploit code published on Exploit-DB
  • 2026-05-16: advisory: CVE-2020-37242 published in NVD

References

Related threats