Description
The Geo Mashup plugin before 1.10.4 for WordPress has insufficient sanitization of post editor and other user input.
References (3)
Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/cyberhobo/wordpress-geo-mashup/issues/817
Patch, Third Party Advisory x_refsource_misc
https://github.com/cyberhobo/wordpress-geo-mashup/commit/838e2fe15a2328f5ae3dfc75d90e420509286f2f
Third Party Advisory x_refsource_misc
https://github.com/cyberhobo/wordpress-geo-mashup/blob/master/readme.txt
Scores
CVSS v3
9.8
EPSS
0.0305
EPSS Percentile
86.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-20
Status
published
Products (1)
cyberhobo/geo_mashup
< 1.10.4
Published
Jul 16, 2018
Tracked Since
Feb 18, 2026