CVE-2026-73376: WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - PHP Object Injection vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
Affected Software
1 affected component
wordpress/plugin/ultimate-maps-by-supsystic<1.5.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Ultimate Maps by Supsystic pluginto a version that resolves this vulnerability.Fixed in 1.5.0
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed and does an attacker need credentials?
Sites using Ultimate Maps by Supsystic versions earlier than 1.5.0 are affected. The issue is unauthenticated, so an attacker does not need a WordPress account or prior privileges.
2
What is the remediation and is a workaround available?
Update the Ultimate Maps by Supsystic plugin to version 1.5.0 or later. The provided information does not identify a temporary mitigation for sites that cannot be updated immediately.
3
How can I determine whether my site is affected?
Check the installed Ultimate Maps by Supsystic plugin version in WordPress. Versions below 1.5.0 should be treated as affected.