Cross-Site Request Forgery in WP-Ultimate-Map Plugin for WordPress
CVE-2026-8907
What is CVE-2026-8907?
The WP-Ultimate-Map plugin for WordPress has a security issue that allows unauthenticated attackers to exploit missing nonce validation. This vulnerability arises in the process_init() function during the admin_init hook, where plugin settings such as zoom-level, focus-lat, focus-lng, sel_places, and sel_routes can be saved without proper verification. An attacker can craft a forged request to trick site administrators into inadvertently changing plugin settings, potentially leading to the injection of malicious scripts. Furthermore, the settings values, especially the zoom-level, are stored unsanitized and later outputted in an HTML attribute and inline JavaScript, heightening the risk of cross-site scripting (XSS) attacks.
Affected Version(s)
WP-Ultimate-Map 0 <= 1.1