Junglewise Threat Intelligence

CVE-2026-48967: Dylan Kuhn Geo Mashup SQL injection in WordPress plugin

CVE-2026-48967 · Severity: high · CVSS 8.5 · Published 2026-06-17

Technologies: Dylan Kuhn Geo Mashup. Vendors: Dylan Kuhn.

Executive brief

Geo Mashup is a WordPress plugin used to integrate interactive maps and location data into websites. A security flaw allows logged-in users with basic 'Subscriber' permissions to execute unauthorized database commands. This could lead to the theft of sensitive site information or disruption of website operations.

Technical details

A SQL injection vulnerability (CWE-89) exists in the Geo Mashup plugin for WordPress in versions up to and including 1.13.19. The flaw allows an authenticated attacker with Subscriber-level permissions to send specially crafted requests to the server, leading to the execution of arbitrary SQL commands. This occurs due to improper neutralization of special elements used in SQL commands. An attacker can leverage this to extract sensitive data from the database or cause limited service disruption. The issue is addressed in version 1.13.20.

Affected products

  • Dylan Kuhn Geo Mashup <= 1.13.19

Timeline

  • 2026-04-23: other: Reported by researcher Baikuya
  • 2026-06-03: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: CVE published to NVD
  • 2026-06-17: patched: Patch confirmed available in version 1.13.20

References

Related threats