Executive brief
Supsystic Ultimate Maps is a WordPress plugin for displaying interactive maps on websites. A missing authorization flaw allows unauthenticated users to access pages or perform actions they shouldn't be able to, such as viewing other users' data, without requiring authentication or proper permission checks.
Technical details
This vulnerability is a broken access control issue (CWE-284) in Supsystic Ultimate Maps plugin through version 1.5.3. The plugin fails to properly validate user permissions before allowing access to sensitive functionality or data. The attack requires no authentication and is reachable over the network via standard HTTP requests. An attacker can exploit this to access restricted pages, view unauthorized data, or perform privileged actions. The vulnerability has been patched in version 1.5.4.
Affected products
- Supsystic Ultimate Maps through 1.5.3
Timeline
- 2026-08-31: disclosed: Reported to Patchstack
- 2026-09-03: advisory: Published by Patchstack and NVD
- 2026-09-03: patched: Version 1.5.4 released