Description
Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions.
Published: 2026-08-13
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw allows an unauthenticated attacker to request arbitrary files from the server, potentially exposing sensitive configuration data, credentials, or other secrets. The vulnerable code in Geo Mashup does not properly sanitize file paths, leading to the inclusion of files not intended for public access.

Affected Systems

WordPress installations that have the Geo Mashup plugin from Dylan Kuhn with a version of 1.13.18 or earlier. The plugin is used to map geographic data, and it may be present on many sites. Users of these specific versions are directly impacted.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.1, indicating high severity. No EPSS score is available, but the lack of authentication requirements makes it attractive for automated exploitation. The vulnerability is not currently listed in the CISA KEV catalog, suggesting no known widespread attacks yet, yet the high score and unrestricted access vector imply significant risk.

Generated by OpenCVE AI on August 13, 2026 at 15:46 UTC.

Remediation

Vendor Solution

Update the WordPress Geo Mashup Plugin to the latest available version (at least 1.13.19).


OpenCVE Recommended Actions

  • Update the Geo Mashup plugin to version 1.13.19 or later to eliminate the LFI flaw.
  • Restrict file permissions and ensure the plugin’s directory is not publicly accessible to prevent unauthorized file reads.
  • If the plugin cannot be updated immediately, consider disabling or uninstalling it to remove the vulnerability from your environment.

Generated by OpenCVE AI on August 13, 2026 at 15:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Dylan Kuhn
Dylan Kuhn geo Mashup
Wordpress
Wordpress wordpress
Vendors & Products Dylan Kuhn
Dylan Kuhn geo Mashup
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions.
Title WordPress Geo Mashup plugin <= 1.13.18 - Local File Inclusion vulnerability
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dylan Kuhn Geo Mashup
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:27:45.822Z

Reserved: 2026-07-27T09:00:28.156Z

Link: CVE-2026-66450

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T14:17:06.147

Modified: 2026-08-13T16:18:43.690

Link: CVE-2026-66450

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:15:03Z

Weaknesses
  • CWE-98

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')