Description
Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.
Published: 2026-09-30
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Unauthenticated Cross Site Scripting
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an unauthenticated cross‑site scripting flaw in the Geo Mashup plugin version 1.13.21 and earlier. It permits the execution of arbitrary JavaScript when site visitors load pages that display the plugin. An attacker could steal session cookies, deface the site, or redirect users to malicious domains, thereby compromising the confidentiality and integrity of the site’s content.

Affected Systems

WordPress installations that have installed the Geo Mashup plugin from Dylan Kuhn and are running any version up to and including 1.13.21 are vulnerable. No other vendors or product families have been identified as affected.

Risk and Exploitability

The CVSS score of 7.1 classifies this flaw as high severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly disclosed exploit use. Based on the description, the attack vector is inferred to be unauthenticated; an attacker only needs to lure a visitor to a page that renders the plugin to trigger the exploit. Because the flaw requires no authentication or privileged access, the exploitation risk is moderate to high for any exposed site.

Generated by OpenCVE AI on September 30, 2026 at 15:32 UTC.

Remediation

Vendor Solution

Update the WordPress Geo Mashup Plugin to the latest available version (at least 1.13.22).


OpenCVE Recommended Actions

  • Update the Geo Mashup plugin to version 1.13.22 or later, which removes the XSS flaw.
  • Search the site for any remaining shortcodes or widgets referencing older plugin instances and remove them to eliminate residual exposure.
  • If the plugin is no longer required, disable or uninstall it to reduce the attack surface.

Generated by OpenCVE AI on September 30, 2026 at 15:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.
Title WordPress Geo Mashup plugin <= 1.13.21 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T13:37:17.941Z

Reserved: 2026-09-24T10:23:10.130Z

Link: CVE-2026-97250

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T13:17:37.110

Modified: 2026-09-30T14:18:16.127

Link: CVE-2026-97250

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T15:45:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')