Cross-Site Scripting Vulnerability in Geo Mashup by Dylan Kuhn
CVE-2026-42734
7.1HIGH
What is CVE-2026-42734?
A Cross-Site Scripting (XSS) vulnerability exists in the Geo Mashup plugin by Dylan Kuhn, allowing malicious attackers to inject arbitrary scripts into web pages viewed by users. This vulnerability affects versions up to 1.13.19, leading to reflected XSS attacks. Users are advised to update to the latest versions and implement security best practices to mitigate risks.
Affected Version(s)
Geo Mashup 0 <= 1.13.19