CVE-2026-73375: WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - Cross Site Scripting (XSS) vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
Affected Software
1 affected component
Supsystic Ultimate Maps (WordPress plugin)<1.5.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Ultimate Maps by Supsystic pluginto a version that resolves this vulnerability.Fixed in 1.5.0
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed, and what does an attacker need to exploit the issue?
Sites using Ultimate Maps by Supsystic versions earlier than 1.5.0 are affected. The issue is remotely reachable and requires no attacker authentication, although exploitation requires user interaction.
2
What should administrators do to remediate this vulnerability?
Upgrade the Ultimate Maps by Supsystic plugin to version 1.5.0 or later. The provided information does not identify a temporary mitigation or workaround.