Skip to content
Noroxi

Geo Mashup

geo-mashup · plugin

Known security vulnerabilities for Geo Mashup. Find out in seconds which version runs on your site with WP Lens.

17 known vulnerabilities

1 critical · 10 exploitable without logging in · 2 with public exploit code · latest Sep 30, 2026

Listed on wordpress.org · latest 1.13.23 · last updated Sep 20, 2026 · 1K+ installs

wordpress.org status checked on Oct 2, 2026

Vulnerabilities

  • CVE-2025-48293unauthenticated≤ 1.13.16

    WordPress Geo Mashup plugin <= 1.13.16 - Local File Inclusion vulnerability

    Critical 9.8
  • CVE-2026-48967subscriber+≤ 1.13.19

    WordPress Geo Mashup plugin <= 1.13.19 - SQL Injection vulnerability

    High 8.5
  • CVE-2026-66450unauthenticated≤ 1.13.18

    WordPress Geo Mashup plugin <= 1.13.18 - Local File Inclusion vulnerability

    High 8.1
  • CVE-2026-4062unauthenticated≤ 1.13.18

    Geo Mashup <= 1.13.18 - Unauthenticated Time-Based SQL Injection via 'object_ids' Parameter

    High 7.5
  • CVE-2026-4061unauthenticated≤ 1.13.18

    Geo Mashup <= 1.13.18 - Unauthenticated Time-Based SQL Injection via 'map_post_type' Parameter

    High 7.5
  • CVE-2026-4060unauthenticated≤ 1.13.18

    Geo Mashup <= 1.13.18 - Unauthenticated Time-Based SQL Injection via 'sort' Parameter

    High 7.5
  • CVE-2026-2416unauthenticated≤ 1.13.17

    Geo Mashup <= 1.13.17 - Unauthenticated SQL Injection via 'sort' Parameter

    High 7.5
  • CVE-2026-97250unauthenticated · needs a click≤ 1.13.21

    WordPress Geo Mashup plugin <= 1.13.21 - Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2026-66449unauthenticated · needs a click≤ 1.13.18

    WordPress Geo Mashup plugin <= 1.13.18 - Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2026-42734unauthenticated · needs a click≤ 1.13.19

    WordPress Geo Mashup plugin <= 1.13.19 - Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2026-27427login required≤ 1.13.18

    WordPress Geo Mashup plugin <= 1.13.18 - Cross Site Scripting (XSS) vulnerability

    Medium 6.5
  • CVE-2026-6457subscriber+≤ 1.13.19

    Geo Mashup <= 1.13.19 - Authenticated (Subscriber+) SQL Injection via 'geo_mashup_null_fields' Parameter

    Medium 6.5
  • CVE-2026-78294contributor+≤ 1.13.21

    WordPress Geo Mashup plugin <= 1.13.21 - Cross Site Scripting (XSS) vulnerability

    Medium 6.5
  • CVE-2024-8990contributor+≤ 1.13.13

    Geo Mashup <= 1.13.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via geo_mashup_visible_posts_list Shortcode

    Medium 6.4
  • CVE-2024-44008login required≤ 1.13.12

    WordPress Geo Mashup plugin <= 1.13.12 - Cross Site Scripting (XSS) vulnerability

    Medium 5.4
  • CVE-2026-7552unauthenticated≤ 1.13.19

    Geo Mashup <= 1.13.19 - Missing Authorization to Unauthenticated Plugin Settings Disclosure via 'geo_mashup_content' Parameter

    Medium 5.3
  • CVE-2015-1383

    Cross-site scripting (XSS) vulnerability in the geo search widget in the Geo Mashup plugin before 1.8.3 for WordPress allows remote attacker

    Medium 4.3

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory