Unauthenticated Local File Inclusion in Geo Mashup by WordPress
CVE-2026-66450

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 August 2026

What is CVE-2026-66450?

The Geo Mashup plugin for WordPress versions up to 1.13.18 is exposed to an unauthenticated local file inclusion vulnerability. This flaw could allow attackers to manipulate file paths in a way that exposes sensitive files on the server. Such exposure may enable unauthorized access to critical information, leading to potential data breaches and exploitation of the affected system. Proper updates and security measures are highly recommended to mitigate these risks and safeguard your WordPress installation.

Affected Version(s)

Geo Mashup <= 1.13.18

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo | Patchstack Bug Bounty Program
.