Description
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated Cross‑Site Scripting flaw in the Ultimate Maps by Supsystic WordPress plugin below version 1.5.0. A malicious user can inject arbitrary JavaScript into pages rendered by the plugin, allowing the execution of scripts in the context of any visitor who views the affected content. This can lead to credential theft, session hijack, or defacement of the site. The weakness is a classic input validation failure, classified as CWE‑79.

Affected Systems

The flaw affects all installations of the Ultimate Maps by Supsystic WordPress plugin with a version lower than 1.5.0. The plugin is developed by Supsystic and is used in WordPress environments for mapping and location‑based content. The vulnerability exists regardless of the specific WordPress theme or other plugins, as long as the vulnerable plugin is active.

Risk and Exploitability

The CVSS base score of 7.1 indicates a moderate to high risk, and because the attack does not require authentication an attacker only needs to send crafted requests to the site. Although no EPSS value is provided, the lack of authentication requirement implies a high exploitation probability. The vulnerability is not currently listed in CISA KEV. An attacker can exploit it via HTTP requests to the plugin’s endpoints, inserting script payloads that are reflected or stored in the map configuration. The impact is site‑wide exposure of visitor browsers, making patching a priority.

Generated by OpenCVE AI on August 18, 2026 at 16:15 UTC.

Remediation

Vendor Solution

Update the WordPress Ultimate Maps by Supsystic Plugin to the latest available version (at least 1.5.0).


OpenCVE Recommended Actions

  • Update the WordPress Ultimate Maps by Supsystic Plugin to version 1.5.0 or later.
  • Disable the plugin from the WordPress dashboard until the update is installed.
  • Deploy a web application firewall or content filtering tool to block reflected and stored XSS payloads.

Generated by OpenCVE AI on August 18, 2026 at 16:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Supsystic
Supsystic ultimate Maps By Supsystic
Wordpress
Wordpress wordpress
Vendors & Products Supsystic
Supsystic ultimate Maps By Supsystic
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
Title WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Supsystic Ultimate Maps By Supsystic
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T15:11:25.615Z

Reserved: 2026-08-12T14:09:17.490Z

Link: CVE-2026-73375

cve-icon Vulnrichment

Updated: 2026-08-18T14:59:41.563Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T15:17:05.270

Modified: 2026-08-20T12:48:31.843

Link: CVE-2026-73375

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:33:23Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')