Cross-Site Request Forgery in WP-Ultimate-Map Plugin for WordPress
CVE-2026-8907

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 June 2026

What is CVE-2026-8907?

The WP-Ultimate-Map plugin for WordPress has a security issue that allows unauthenticated attackers to exploit missing nonce validation. This vulnerability arises in the process_init() function during the admin_init hook, where plugin settings such as zoom-level, focus-lat, focus-lng, sel_places, and sel_routes can be saved without proper verification. An attacker can craft a forged request to trick site administrators into inadvertently changing plugin settings, potentially leading to the injection of malicious scripts. Furthermore, the settings values, especially the zoom-level, are stored unsanitized and later outputted in an HTML attribute and inline JavaScript, heightening the risk of cross-site scripting (XSS) attacks.

Affected Version(s)

WP-Ultimate-Map 0 <= 1.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Nur Ibnu Hubab
.