CVE-2026-97250: WordPress Geo Mashup plugin <= 1.13.21 - Cross Site Scripting (XSS) vulnerability
Published Sep 30, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.
Affected Software
1 affected component
WordPress Geo Mashup<=1.13.21
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Geo Mashup Pluginto a version that resolves this vulnerability.Fixed in 1.13.22
Event History
Sep 30, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The issue is described as unauthenticated, so the attacker does not need a WordPress account or other prior privileges. Exploitation requires user interaction, as indicated by the UI:R vector.
2
Which installations should be treated as affected?
WordPress sites using the Geo Mashup plugin at version 1.13.21 or earlier should be treated as affected based on the available information.