Impact
The Geo Mashup plugin for WordPress up to version 1.13.21 contains a contributor‑level Cross Site Scripting vulnerability (CWE‑79). An attacker with contributor access or who can trick a user into submitting malicious content can inject unsanitized JavaScript into the plugin’s rendered output. The injected script runs in the browsers of any visitor viewing the affected pages, allowing cookie theft, session hijacking, defacement, or other client‑side compromise.
Affected Systems
All installations of Dylan Kuhn’s Geo Mashup plugin version 1.13.21 or earlier on WordPress sites are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score is not available, so the likelihood of exploitation is unknown. The attack vector is inferred to be through the plugin’s administrative or content‑submission interface, requiring an attacker to supply malicious payloads as a contributor. The vulnerability is not listed in the CISA KEV catalog, but sites that accept user‑generated content via Geo Mashup should treat the risk as significant.
OpenCVE Enrichment