Executive brief
Geo Mashup is a WordPress plugin used to save and display location information for posts and pages. A security flaw allows users with low-level permissions, such as contributors, to inject malicious scripts into the website. These scripts can then execute in the browsers of other visitors or administrators, potentially leading to unauthorized actions, website defacement, or redirection to malicious sites.
Technical details
The Geo Mashup plugin for WordPress (versions <= 1.13.18) contains a Stored Cross-Site Scripting (XSS) vulnerability. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with 'Contributor' level privileges or higher can inject malicious HTML or JavaScript payloads that are stored on the server. When a victim (such as an administrator) views the affected page, the script executes in their browser context. This can lead to session hijacking or unauthorized administrative actions. The issue is resolved in version 1.13.19.
Affected products
- Dylan Kuhn Geo Mashup up to 1.13.18
Timeline
- 2025-10-20: other: Reported by Muhammad Yudha - DJ
- 2026-05-26: advisory: Published by Patchstack
- 2026-05-26: patched: Version 1.13.19 released