Cross-Site Scripting Vulnerability in Geo Mashup by Dylan Kuhn
CVE-2026-42734

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 May 2026

What is CVE-2026-42734?

A Cross-Site Scripting (XSS) vulnerability exists in the Geo Mashup plugin by Dylan Kuhn, allowing malicious attackers to inject arbitrary scripts into web pages viewed by users. This vulnerability affects versions up to 1.13.19, leading to reflected XSS attacks. Users are advised to update to the latest versions and implement security best practices to mitigate risks.

Affected Version(s)

Geo Mashup 0 <= 1.13.19

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

she11f | Patchstack Bug Bounty Program
.