Impact
The vulnerability is a stored Cross‑Site Scripting flaw that allows an attacker to inject malicious scripts into web pages served by the Geo Mashup plugin. If executed, these scripts run within the browser context of any user who views the affected page, enabling attackers to exfiltrate credentials, deface content, or hijack user sessions. The weakness arises from improper neutralization of user input during page generation (CWE‑79).
Affected Systems
The affected product is the Geo Mashup plugin created by Dylan Kuhn for WordPress. Versions from the initial release through 1.13.18 are vulnerable; any deployment using those versions should be considered at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability. No EPSS score is currently available, so the exact likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. Attackers typically need to supply crafted input that the plugin stores and later renders on a page, and the compromised script then runs in the context of any visitor to that page. The risk is higher on sites that allow arbitrary content creation by users or expose the plugin’s data to the public.
OpenCVE Enrichment