Junglewise Threat Intelligence

CVE-2025-15345: MapGeo Interactive Geo Maps reflected XSS in display-map shortcode

CVE-2025-15345 · Severity: medium · CVSS 6.1 · Published 2026-05-14

Executive brief

The MapGeo plugin for WordPress, which is used to display interactive maps on websites, contains a security flaw that allows for reflected cross-site scripting. An attacker can trick a user into clicking a malicious link, which then executes unauthorized code in the user's browser. This could lead to the theft of sensitive session information or unauthorized actions being performed on behalf of the user.

Technical details

The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'map' parameter within the 'display-map' shortcode. This vulnerability exists in all versions up to and including 1.6.27. An unauthenticated remote attacker can exploit this by crafting a malicious URL and tricking a user into clicking it. If successful, the attacker can execute arbitrary JavaScript in the context of the victim's browser session. The issue was addressed in version 1.6.28.

Affected products

  • MapGeo MapGeo – Interactive Geo Maps Up to, and including, 1.6.27

Timeline

  • 2026-05-14: disclosed: CVE published to NVD dataset
  • 2026-05-14: advisory: Wordfence published vulnerability details

References