Junglewise Threat Intelligence

CVE-2026-7552: Geo Mashup WordPress plugin authorization bypass

CVE-2026-7552 · Severity: medium · CVSS 5.3 · Published 2026-05-28

Technologies: Geo Mashup.

Executive brief

The Geo Mashup plugin for WordPress, which is used to integrate maps and location data into websites, contains a security flaw that allows unauthorized access to its settings. An attacker can exploit this to view sensitive information, such as Google Maps API keys and GeoNames service credentials. This could lead to unauthorized use of paid map services or further exploitation of the website's integrated services.

Technical details

The Geo Mashup plugin for WordPress suffers from a missing authorization vulnerability (CWE-862) in versions up to 1.13.19. The root cause is a failure to properly verify user permissions before performing certain actions or displaying configuration data. An unauthenticated attacker can exploit this over the network to retrieve sensitive plugin settings, specifically Google Maps API keys and GeoNames service credentials. This information disclosure occurs because the plugin does not implement sufficient access control checks on its administrative or configuration endpoints. A patch appears to be available in the plugin's trunk/latest versions via changeset 3503627.

Affected products

  • Geo Mashup Geo Mashup Up to, and including, 1.13.19

Timeline

  • 2026-05-28: disclosed: Vulnerability published to the CVE list
  • 2026-05-28: advisory: NVD and Wordfence advisories published

References