Impact
The Geo Mashup plugin for WordPress allows unauthenticated users to retrieve sensitive configuration data because the plugin fails to verify authorization for the 'geo_mashup_content' parameter. This bypass can expose embedded Google Maps API keys and GeoNames credentials, compromising the confidentiality of the site's mapping services.
Affected Systems
WordPress installations running any Geo Mashup plugin version 1.13.19 or earlier are affected. The issue is present across all versions up to the specified release. Sites that rely on this plugin for embedded maps or location‑based functionality should review their current plugin version.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available. Because the vulnerability can be exploited by any external actor without authentication and requires only a crafted request, the attack vector is straightforward. Although the vulnerability is not listed in the CISA KEV catalog, the potential exposure of API keys and credentials represents a noteworthy risk. An adversary with knowledge of the plugin could easily retrieve the configuration values and misuse them for unauthorized mapping activity or API abuse.
OpenCVE Enrichment