Description
Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.
Published: 2026-09-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Scripting that allows arbitrary script execution in site visitor browsers
Action: Apply Patch
AI Analysis

Impact

The Geo Mashup plugin for WordPress up to version 1.13.21 contains a contributor‑level Cross Site Scripting vulnerability (CWE‑79). An attacker with contributor access or who can trick a user into submitting malicious content can inject unsanitized JavaScript into the plugin’s rendered output. The injected script runs in the browsers of any visitor viewing the affected pages, allowing cookie theft, session hijacking, defacement, or other client‑side compromise.

Affected Systems

All installations of Dylan Kuhn’s Geo Mashup plugin version 1.13.21 or earlier on WordPress sites are affected.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score is not available, so the likelihood of exploitation is unknown. The attack vector is inferred to be through the plugin’s administrative or content‑submission interface, requiring an attacker to supply malicious payloads as a contributor. The vulnerability is not listed in the CISA KEV catalog, but sites that accept user‑generated content via Geo Mashup should treat the risk as significant.

Generated by OpenCVE AI on September 17, 2026 at 22:27 UTC.

Remediation

Vendor Solution

Update the WordPress Geo Mashup Plugin to the latest available version (at least 1.13.22).


OpenCVE Recommended Actions

  • Update the Geo Mashup plugin to version 1.13.22 or later
  • If the plugin is unnecessary, uninstall or deactivate it to eliminate the exposure
  • Restrict content submission to trusted users by tightening WordPress role permissions or adding additional input sanitization to the plugin

Generated by OpenCVE AI on September 17, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Dylan Kuhn
Dylan Kuhn geo Mashup
Wordpress
Wordpress wordpress
Vendors & Products Dylan Kuhn
Dylan Kuhn geo Mashup
Wordpress
Wordpress wordpress

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.
Title WordPress Geo Mashup plugin <= 1.13.21 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Dylan Kuhn Geo Mashup
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-19T14:21:53.594Z

Reserved: 2026-08-24T07:38:18.805Z

Link: CVE-2026-78294

cve-icon Vulnrichment

Updated: 2026-09-19T14:15:59.421Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:30.167

Modified: 2026-09-19T15:17:02.180

Link: CVE-2026-78294

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')