Description
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions.
Published: 2026-09-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a broken access control flaw that may allow unauthenticated users to access or manipulate plugin resources that should be protected. The specific capabilities are not detailed in the CVE description, and this analysis does not assume that attackers can create or modify map entries. Based on the description, the flaw could affect the integrity and confidentiality of data managed by the plugin, but it does not grant system‑level privileges.

Affected Systems

The issue affects the WordPress Ultimate Maps by Supsystic plugin, versions 1.5.5 and earlier. Site owners running any of these versions on a WordPress installation are exposed. Upgrade to 1.6.1 or later resolves the problem.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity vulnerability. EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The flaw can be exploited remotely via the web interface, and because it does not require authentication, privilege escalation is not required. Attackers could potentially access plugin functionality that should be restricted, leading to data exposure or tampering; however, the CVE description does not disclose the specific capabilities an attacker could gain. This analysis does not assume any particular action beyond what is stated.

Generated by OpenCVE AI on September 30, 2026 at 19:54 UTC.

Remediation

Vendor Solution

Update the WordPress Ultimate Maps by Supsystic plugin to the latest available version (at least 1.6.1).


OpenCVE Recommended Actions

  • Upgrade the WordPress Ultimate Maps by Supsystic plugin to version 1.6.1 or later.
  • If an upgrade is not immediately possible, restrict access to the plugin’s admin pages by IP whitelisting or firewall rules to limit who can reach the endpoints.
  • Disable the plugin on sites that do not require map functionality until an update can be applied.

Generated by OpenCVE AI on September 30, 2026 at 19:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions.
Title WordPress Ultimate Maps by Supsystic plugin <= 1.5.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T17:59:56.305Z

Reserved: 2026-09-29T00:15:56.342Z

Link: CVE-2026-102397

cve-icon Vulnrichment

Updated: 2026-09-30T17:59:32.607Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T18:18:14.863

Modified: 2026-09-30T19:04:41.917

Link: CVE-2026-102397

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T20:00:11Z

Weaknesses