Cross Site Scripting Vulnerability in Geo Mashup Plugin by WordPress
CVE-2026-78294

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 September 2026

What is CVE-2026-78294?

The Geo Mashup plugin for WordPress, specifically versions up to 1.13.21, is susceptible to a Cross Site Scripting (XSS) vulnerability. When exploited, this flaw allows malicious users to inject arbitrary scripts into web pages viewed by other users. Attackers could leverage this vulnerability to perform actions such as stealing user cookies, session tokens, or executing harmful scripts on behalf of unsuspecting users, significantly compromising the security and integrity of affected websites. Website administrators should promptly update to the latest version of the plugin to mitigate the risk associated with this vulnerability.

Affected Version(s)

Geo Mashup <= 1.13.21

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

JunHee CHO | Patchstack Bug Bounty Program
.