CVE-2026-85309: WordPress Ultimate Maps by Supsystic plugin <= 1.5.3 - Broken Access Control vulnerability
Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Ultimate Maps by Supsystic: from n/a through 1.5.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Ultimate Maps by Supsystic (Supsystic Ultimate Maps by Supsystic)to a version that resolves this vulnerability.Fixed in 1.5.4
Event History
Frequently Asked Questions
Which installations are affected?
Ultimate Maps by Supsystic versions through 1.5.3 are affected. The available data does not identify a lower affected version boundary.
Does exploitation require authentication or user interaction?
No. The CVSS vector indicates exploitation is network-accessible, requires no privileges, and does not require user interaction.
What is the expected impact of successful exploitation?
The reported impact is limited to integrity, with no reported confidentiality or availability impact. The CVSS base score is 5.3 (medium).