Junglewise Threat Intelligence

CVE-2026-85309: Supsystic Ultimate Maps broken access control vulnerability

CVE-2026-85309 · Severity: medium · CVSS 5.3 · Published 2026-09-03

Vendors: Supsystic.

Executive brief

Supsystic Ultimate Maps is a WordPress plugin for displaying interactive maps on websites. A missing authorization flaw allows unauthenticated users to access pages or perform actions they shouldn't be able to, such as viewing other users' data, without requiring authentication or proper permission checks.

Technical details

This vulnerability is a broken access control issue (CWE-284) in Supsystic Ultimate Maps plugin through version 1.5.3. The plugin fails to properly validate user permissions before allowing access to sensitive functionality or data. The attack requires no authentication and is reachable over the network via standard HTTP requests. An attacker can exploit this to access restricted pages, view unauthorized data, or perform privileged actions. The vulnerability has been patched in version 1.5.4.

Affected products

  • Supsystic Ultimate Maps through 1.5.3

Timeline

  • 2026-08-31: disclosed: Reported to Patchstack
  • 2026-09-03: advisory: Published by Patchstack and NVD
  • 2026-09-03: patched: Version 1.5.4 released

References

Related threats