Description
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
Published: 2026-08-18
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated Cross‑Site Scripting flaw in the Ultimate Maps by Supsystic WordPress plugin below version 1.5.0. A malicious user can inject arbitrary JavaScript into pages rendered by the plugin, allowing the execution of scripts in the context of any visitor who views the affected content. This can lead to credential theft, session hijack, or defacement of the site. The weakness is a classic input validation failure, classified as CWE‑79.

Affected Systems

The flaw affects all installations of the Ultimate Maps by Supsystic WordPress plugin with a version lower than 1.5.0. The plugin is developed by Supsystic and is used in WordPress environments for mapping and location‑based content. The vulnerability exists regardless of the specific WordPress theme or other plugins, as long as the vulnerable plugin is active.

Risk and Exploitability

The CVSS base score of 7.1 indicates a moderate to high risk, and because the attack does not require authentication an attacker only needs to send crafted requests to the site. Although no EPSS value is provided, the lack of authentication requirement implies a high exploitation probability. The vulnerability is not currently listed in CISA KEV. An attacker can exploit it via HTTP requests to the plugin’s endpoints, inserting script payloads that are reflected or stored in the map configuration. The impact is site‑wide exposure of visitor browsers, making patching a priority.

Generated by OpenCVE AI on August 18, 2026 at 16:15 UTC.

Remediation

Vendor Solution

Update the WordPress Ultimate Maps by Supsystic Plugin to the latest available version (at least 1.5.0).


OpenCVE Recommended Actions

  • Update the WordPress Ultimate Maps by Supsystic Plugin to version 1.5.0 or later.
  • Disable the plugin from the WordPress dashboard until the update is installed.
  • Deploy a web application firewall or content filtering tool to block reflected and stored XSS payloads.

Generated by OpenCVE AI on August 18, 2026 at 16:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
Title WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T15:11:25.615Z

Reserved: 2026-08-12T14:09:17.490Z

Link: CVE-2026-73375

cve-icon Vulnrichment

Updated: 2026-08-18T14:59:41.563Z

cve-icon NVD

Status : Received

Published: 2026-08-18T15:17:05.270

Modified: 2026-08-18T15:17:05.270

Link: CVE-2026-73375

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T16:30:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')