Impact
The vulnerability is an unauthenticated cross‑site scripting flaw in the Geo Mashup plugin version 1.13.21 and earlier. It permits the execution of arbitrary JavaScript when site visitors load pages that display the plugin. An attacker could steal session cookies, deface the site, or redirect users to malicious domains, thereby compromising the confidentiality and integrity of the site’s content.
Affected Systems
WordPress installations that have installed the Geo Mashup plugin from Dylan Kuhn and are running any version up to and including 1.13.21 are vulnerable. No other vendors or product families have been identified as affected.
Risk and Exploitability
The CVSS score of 7.1 classifies this flaw as high severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly disclosed exploit use. Based on the description, the attack vector is inferred to be unauthenticated; an attacker only needs to lure a visitor to a page that renders the plugin to trigger the exploit. Because the flaw requires no authentication or privileged access, the exploitation risk is moderate to high for any exposed site.
OpenCVE Enrichment