Executive brief
Geo Mashup is a WordPress plugin used to integrate maps and geographic data into website content. A security flaw in this plugin allows attackers to trick a user into clicking a malicious link, which then executes unauthorized code in the user's browser. This can lead to the theft of login sessions, unauthorized website changes, or the redirection of visitors to malicious sites.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Dylan Kuhn Geo Mashup plugin for WordPress due to improper neutralization of user-supplied input during web page generation. The flaw is present in versions up to and including 1.13.19. An unauthenticated remote attacker can exploit this by enticing a user to visit a specially crafted URL. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized actions. The issue is resolved in version 1.13.20.
Affected products
- Dylan Kuhn Geo Mashup <= 1.13.19
Timeline
- 2026-04-26: other: Vulnerability reported by researcher she11f
- 2026-05-26: advisory: Patchstack advisory published
- 2026-05-27: disclosed: NVD publication date
- 2026-05-26: patched: Version 1.13.20 released to address the issue