Executive brief
Geo Mashup is a WordPress plugin that adds interactive map functionality to websites. This vulnerability allows contributors (users with low-level editing permissions) to inject malicious scripts into the site through a stored XSS flaw. If exploited, an attacker could steal visitor data, hijack user accounts, or deface the website—though successful exploitation requires a privileged user to be tricked into interacting with malicious content.
Technical details
This is a stored Cross-Site Scripting (XSS) vulnerability in Geo Mashup versions up to 1.13.21. The vulnerability exists due to insufficient input sanitization, allowing contributors to inject malicious JavaScript code that persists in the database. Attack requires elevated user privileges (Contributor role or higher) to inject the payload, but the script executes in the context of site visitors or administrators, potentially stealing sessions or sensitive data. The vulnerability has been patched in version 1.13.22 and later.
Affected products
- Geo Mashup Geo Mashup ≤ 1.13.21
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Fixed in version 1.13.22