CVE-2026-102396: WordPress Ultimate Maps by Supsystic plugin <= 1.5.5 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Ultimate Maps by Supsysticto a version that resolves this vulnerability.Fixed in 1.6.1
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The issue is described as unauthenticated, so an attacker does not need an account or existing WordPress privileges. Exploitation still requires user interaction, as indicated by the UI:R vector.
Which installations are known to be affected?
Ultimate Maps by Supsystic plugin versions 1.5.5 and earlier are identified as affected. The provided data does not state whether a particular plugin configuration or feature must be enabled.
What is the potential impact if exploitation succeeds?
The supplied CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed. As an XSS issue, successful exploitation can run attacker-supplied script in a victim's browser context.