CVE-2026-73377: WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - Broken Access Control vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.
Affected Software
1 affected component
wordpress/ultimate-maps-by-supsystic<1.5.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Ultimate Maps by Supsystic pluginto a version that resolves this vulnerability.Fixed in 1.5.0
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed?
Sites using Ultimate Maps by Supsystic versions earlier than 1.5.0 are affected. The vulnerability is network-accessible and requires no authentication or user interaction.
2
What should be done to remediate the issue?
The issue allows unauthenticated broken access control and can affect integrity. Update the plugin to version 1.5.0 or later.