Reflected Cross-Site Scripting in MapGeo Interactive Geo Maps Plugin for WordPress
CVE-2025-15345
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 May 2026
What is CVE-2025-15345?
The MapGeo β Interactive Geo Maps plugin for WordPress is susceptible to Reflected Cross-Site Scripting (XSS) via the 'map' parameter in the display-map shortcode. This arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to insert arbitrary scripts into pages. If a user is tricked into clicking a malicious link, the injected script can execute in their browser context, potentially compromising sensitive user information and leading to broader security issues.
Affected Version(s)
MapGeo β Interactive Geo Maps 0 <= 1.6.27