Junglewise Threat Intelligence

CVE-2026-42734: Dylan Kuhn Geo Mashup Reflected XSS

CVE-2026-42734 · Severity: high · CVSS 7.1 · Published 2026-05-27

Technologies: Dylan Kuhn Geo Mashup. Vendors: Dylan Kuhn.

Executive brief

Geo Mashup is a WordPress plugin used to integrate maps and geographic data into website content. A security flaw in this plugin allows attackers to trick a user into clicking a malicious link, which then executes unauthorized code in the user's browser. This can lead to the theft of login sessions, unauthorized website changes, or the redirection of visitors to malicious sites.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Dylan Kuhn Geo Mashup plugin for WordPress due to improper neutralization of user-supplied input during web page generation. The flaw is present in versions up to and including 1.13.19. An unauthenticated remote attacker can exploit this by enticing a user to visit a specially crafted URL. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized actions. The issue is resolved in version 1.13.20.

Affected products

  • Dylan Kuhn Geo Mashup <= 1.13.19

Timeline

  • 2026-04-26: other: Vulnerability reported by researcher she11f
  • 2026-05-26: advisory: Patchstack advisory published
  • 2026-05-27: disclosed: NVD publication date
  • 2026-05-26: patched: Version 1.13.20 released to address the issue

References

Related threats