Sceawere

Vulnerability Detail

CVE-2026-102396UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated XSS in Ultimate Maps

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
supsystic
Product
Ultimate Maps by Supsystic
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-09-30T13:17:17.513Z",
  "pubdate": "2026-09-30T13:17:17.513Z",
  "executiveSummary": "The Ultimate Maps by Supsystic plugin, in versions 1.5.5 and below, contains an unauthenticated Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability allows unauthenticated remote attackers to inject arbitrary client-side scripts into the victim's browser context.\nThe impact includes the potential for session hijacking, unauthorized actions performed on behalf of authenticated administrators, and the redirection of users to malicious websites.\nThe flaw stems from improper neutralization of user-supplied input before rendering it within the web interface.\nBecause the vulnerability is unauthenticated, exploitation does not require prior knowledge of administrator credentials or elevated access rights.\nThe risk is critical for websites leveraging this plugin, as attackers can weaponize the vulnerability to compromise administrative sessions or perform phishing attacks against legitimate users browsing the site.\nImmediate action is required to mitigate the risk, primarily through updating the plugin to a patched version or implementing strict content security policies to restrict script execution.",
  "technicalDetails": "The vulnerability is a stored or reflected XSS flaw residing within the Ultimate Maps by Supsystic plugin. The root cause is the failure of the application to properly sanitize or validate user-supplied parameters before echoing them into the Document Object Model (DOM) of the rendered web page.\nIn a typical attack flow, the attacker identifies an unsanitized input vector within the plugin's front-end or administrative configuration parameters. By crafting a malicious URI containing a JavaScript payload (e.g., <script>alert(document.cookie)</script>), an attacker can force the application to reflect this script back to any user who visits the generated URL.\nBecause the input is processed server-side and returned without adequate output encoding, the browser interprets the injected string as legitimate executable code rather than plain text. This executes the payload within the security context of the user's current session.\nThe vulnerability is accessible without authentication, meaning the attacker does not need to bypass a login page or possess valid session tokens to trigger the execution of the payload. The attack vector is exposed via the network, targeting any visitor or administrator interacting with the vulnerable plugin component.\nPost-exploitation impact is severe. Successful execution of the payload allows an attacker to perform actions in the context of the victim's session, such as stealing session cookies, modifying site content, or deploying further malicious payloads via the WordPress administrative dashboard if an administrator is targeted. Furthermore, the attacker can manipulate the DOM to present fake login forms, facilitating credential harvesting.\nThe lack of appropriate context-aware output encoding functions within the affected code modules allows for the injection of arbitrary HTML and JavaScript. This bypasses typical browser-based XSS filters unless advanced Content Security Policies are strictly enforced. The vulnerability remains present in all versions 1.5.5 and below, necessitating a code-level remediation to sanitize inputs or encode outputs using appropriate WordPress functions such as esc_html() or esc_js()."
}
CVE-2026-102396: Unauthenticated XSS in Ultimate Maps (HIGH Severity, CVSS: 7.1) | Sceawere