Junglewise Threat Intelligence

CVE-2026-81770: Interactive Geo Maps cross-site scripting vulnerability

CVE-2026-81770 · Severity: high · CVSS 7.1 · Published 2026-09-02

Executive brief

Interactive Geo Maps is a WordPress plugin used to display interactive maps on websites. An unauthenticated attacker can inject malicious scripts into the plugin that execute in visitors' browsers, potentially stealing their data or hijacking their accounts. The vulnerability affects all versions up to 1.6.30 and does not require any authentication or special privileges to exploit.

Technical details

The vulnerability is a reflected cross-site scripting (XSS) flaw in Interactive Geo Maps plugin versions up to 1.6.30. An unauthenticated attacker can inject malicious scripts that are rendered in the browsers of site visitors who click a crafted link or visit a compromised page. The attack requires user interaction (a victim must click a malicious link or visit a crafted page). Successful exploitation allows attackers to steal sensitive visitor data or perform actions on behalf of users. No official patch is currently available; temporary mitigation is available through security plugins like Patchstack.

Affected products

  • Interactive Geo Maps Interactive Geo Maps <=1.6.30

Timeline

  • 2026-09-02: disclosed
  • 2026-09-01: advisory: Patchstack published advisory

References