Unauthenticated XSS Vulnerability in Interactive Geo Maps Plugin by WordPress
CVE-2026-81770

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 September 2026

What is CVE-2026-81770?

The Interactive Geo Maps plugin for WordPress is vulnerable to reflected Cross Site Scripting (XSS), which can be exploited by attackers to execute arbitrary JavaScript code in the context of a user's session. This vulnerability arises from improper input validation, allowing malicious scripts to be injected through the plugin's features. Users running versions 1.6.30 or lower should consider updating to mitigate potential risks.

Affected Version(s)

Interactive Geo Maps <= 1.6.30

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

timomangcut | Patchstack Bug Bounty Program
.