Cross Site Scripting Vulnerability in Geo Mashup WordPress Plugin
CVE-2026-97250
7.1HIGH
What is CVE-2026-97250?
The Geo Mashup WordPress plugin versions up to 1.13.21 have a security flaw that allows unauthenticated users to execute arbitrary JavaScript code in the context of a user's browser session. This Cross Site Scripting (XSS) vulnerability can potentially lead to session hijacking or redirection to malicious sites, undermining the integrity of user data and overall site security.
Affected Version(s)
Geo Mashup <= 1.13.21