Authorization Bypass in Geo Mashup Plugin for WordPress
CVE-2026-7552

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
28 May 2026

What is CVE-2026-7552?

The Geo Mashup plugin for WordPress contains a significant vulnerability due to inadequate verification of user authorization. This issue allows attackers without authentication to gain access to sensitive configuration information, such as Google Maps API keys and GeoNames service credentials. This exposure can lead to unauthorized and malicious use of these credentials, compromising the security of the affected websites. It is crucial for users of Geo Mashup to update to the latest version to mitigate this risk.

Affected Version(s)

Geo Mashup 0 <= 1.13.19

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Minh Toan
.