Geo Mashup
geo-mashup · plugin
Known security vulnerabilities for Geo Mashup. Find out in seconds which version runs on your site with WP Lens.
17 known vulnerabilities
1 critical · 10 exploitable without logging in · 2 with public exploit code · latest Sep 30, 2026
Listed on wordpress.org · latest 1.13.23 · last updated Sep 20, 2026 · 1K+ installs
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- Critical 9.8
CVE-2025-48293unauthenticated≤ 1.13.16
WordPress Geo Mashup plugin <= 1.13.16 - Local File Inclusion vulnerability
- High 8.5
CVE-2026-48967subscriber+≤ 1.13.19
WordPress Geo Mashup plugin <= 1.13.19 - SQL Injection vulnerability
- High 8.1
CVE-2026-66450unauthenticated≤ 1.13.18
WordPress Geo Mashup plugin <= 1.13.18 - Local File Inclusion vulnerability
- High 7.5
CVE-2026-4062unauthenticated≤ 1.13.18
Geo Mashup <= 1.13.18 - Unauthenticated Time-Based SQL Injection via 'object_ids' Parameter
- High 7.5
CVE-2026-4061unauthenticated≤ 1.13.18
Geo Mashup <= 1.13.18 - Unauthenticated Time-Based SQL Injection via 'map_post_type' Parameter
- High 7.5
CVE-2026-4060unauthenticated≤ 1.13.18
Geo Mashup <= 1.13.18 - Unauthenticated Time-Based SQL Injection via 'sort' Parameter
- High 7.5
CVE-2026-2416unauthenticated≤ 1.13.17
Geo Mashup <= 1.13.17 - Unauthenticated SQL Injection via 'sort' Parameter
- High 7.1
CVE-2026-97250unauthenticated · needs a click≤ 1.13.21
WordPress Geo Mashup plugin <= 1.13.21 - Cross Site Scripting (XSS) vulnerability
- High 7.1
CVE-2026-66449unauthenticated · needs a click≤ 1.13.18
WordPress Geo Mashup plugin <= 1.13.18 - Cross Site Scripting (XSS) vulnerability
- High 7.1
CVE-2026-42734unauthenticated · needs a click≤ 1.13.19
WordPress Geo Mashup plugin <= 1.13.19 - Cross Site Scripting (XSS) vulnerability
- Medium 6.5
CVE-2026-27427login required≤ 1.13.18
WordPress Geo Mashup plugin <= 1.13.18 - Cross Site Scripting (XSS) vulnerability
- Medium 6.5
CVE-2026-6457subscriber+≤ 1.13.19
Geo Mashup <= 1.13.19 - Authenticated (Subscriber+) SQL Injection via 'geo_mashup_null_fields' Parameter
- Medium 6.5
CVE-2026-78294contributor+≤ 1.13.21
WordPress Geo Mashup plugin <= 1.13.21 - Cross Site Scripting (XSS) vulnerability
- Medium 6.4
CVE-2024-8990contributor+≤ 1.13.13
Geo Mashup <= 1.13.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via geo_mashup_visible_posts_list Shortcode
- Medium 5.4
CVE-2024-44008login required≤ 1.13.12
WordPress Geo Mashup plugin <= 1.13.12 - Cross Site Scripting (XSS) vulnerability
- Medium 5.3
CVE-2026-7552unauthenticated≤ 1.13.19
Geo Mashup <= 1.13.19 - Missing Authorization to Unauthenticated Plugin Settings Disclosure via 'geo_mashup_content' Parameter
- Medium 4.3
Cross-site scripting (XSS) vulnerability in the geo search widget in the Geo Mashup plugin before 1.8.3 for WordPress allows remote attacker
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).