Description
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated broken access control in the Ultimate Maps by Supsystic WordPress plugin allows an attacker to read, modify, or delete map data and potentially other plugin settings without authentication. This flaw is a privilege escalation weakness (CWE‑862), compromising confidentiality, integrity, and availability of the site’s mapping content.

Affected Systems

The vulnerability affects all installations of WordPress Ultimate Maps by Supsystic that run versions older than 1.5.0. Site administrators should verify the plugin version and plan an upgrade if applicable.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. EPSS data is not available and the flaw is not listed in CISA KEV, suggesting that large‑scale public exploits have not yet been observed. The likely attack vector is web‑based: any visitor to the site can trigger the flaw to elevate privileges within the plugin. Monitoring and timely patching remain crucial for mitigating this risk.

Generated by OpenCVE AI on August 18, 2026 at 17:25 UTC.

Remediation

Vendor Solution

Update the WordPress Ultimate Maps by Supsystic Plugin to the latest available version (at least 1.5.0).


OpenCVE Recommended Actions

  • Update the WordPress Ultimate Maps by Supsystic plugin to version 1.5.0 or later
  • If an immediate upgrade is not possible, disable or uninstall the plugin to prevent map data manipulation
  • Configure role‑based access controls so that plugin API endpoints are accessible only to administrators

Generated by OpenCVE AI on August 18, 2026 at 17:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Supsystic
Supsystic ultimate Maps By Supsystic
Wordpress
Wordpress wordpress
Vendors & Products Supsystic
Supsystic ultimate Maps By Supsystic
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.
Title WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Supsystic Ultimate Maps By Supsystic
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T19:48:19.960Z

Reserved: 2026-08-12T14:09:17.490Z

Link: CVE-2026-73377

cve-icon Vulnrichment

Updated: 2026-08-18T19:39:21.891Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T15:17:05.550

Modified: 2026-08-20T12:48:31.843

Link: CVE-2026-73377

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:33:19Z

Weaknesses