CVE-2026-78294: WordPress Geo Mashup plugin <= 1.13.21 - Cross Site Scripting (XSS) vulnerability
Published Sep 17, 2026
·Updated
Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.
Affected Software
1 affected component
Geo Mashup<=1.13.21
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Geo Mashup pluginto a version that resolves this vulnerability.Fixed in 1.13.22
Event History
Sep 17, 2026
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs Contributor-level access to the WordPress site. Exploitation also requires user interaction.
2
What is the potential impact if exploited?
The issue can allow cross-site scripting with low impact to confidentiality, integrity, and availability. The scope is changed, meaning the impact may extend beyond the vulnerable component.
3
Which Geo Mashup versions are affected?
Geo Mashup versions up to and including 1.13.21 are affected.