Sceawere

Vulnerability Detail

CVE-2026-97250UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated XSS in Geo Mashup

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
Dylan Kuhn
Product
Geo Mashup
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-09-30T13:17:37.110Z",
  "pubdate": "2026-09-30T13:17:37.110Z",
  "executiveSummary": "An unauthenticated Cross-Site Scripting (XSS) vulnerability exists in Geo Mashup versions 1.13.21 and earlier.\nThis vulnerability allows an unauthenticated remote attacker to inject and execute arbitrary JavaScript code within the context of a victim's browser session when accessing the affected WordPress site.\nThe flaw stems from insufficient input validation and output sanitization of parameters handled by the plugin, enabling the injection of malicious scripts.\nSuccessful exploitation can lead to unauthorized actions performed on behalf of authenticated users, session hijacking, credential theft, and redirection to malicious external domains.\nThe risk is categorized as high due to the potential for full account compromise and the lack of authentication required for exploitation, making it accessible to any external attacker.\nAll users operating versions 1.13.21 or lower are potentially exposed to site-wide compromises if an attacker crafts a malicious link or injects content that is rendered by the affected plugin.",
  "technicalDetails": "The vulnerability is identified as a reflected or stored Cross-Site Scripting (XSS) flaw, depending on the specific implementation of the endpoint, originating from the application's failure to adequately sanitize user-supplied input before rendering it in the HTML response.\nRoot cause analysis indicates that Geo Mashup processes parameters through its plugin functionality without applying strict output encoding or context-aware filtering. When the plugin dynamically generates UI elements or map configurations based on these user-controlled inputs, the lack of sanitization allows the injection of script tags or event handlers (e.g., onerror, onload).\nThe attack flow typically involves an attacker identifying an input vector—such as a URL parameter or a POST request variable—that is reflected by the Geo Mashup plugin on a front-facing page. By crafting a specific URL containing a malicious JavaScript payload, the attacker lures an authenticated administrator or a general user into clicking the link.\nOnce the victim accesses the crafted URL, the browser executes the injected script within the security context of the vulnerable WordPress instance. This bypasses the Same-Origin Policy (SOP) because the script originates from the trusted domain.\nThe affected component is primarily the plugin's map rendering engine and its associated administrative or frontend parameter handling logic. Since this vulnerability is unauthenticated, no prior knowledge of the target system's credentials is required; the exploit relies entirely on the victim visiting the manipulated URL.\nPost-exploitation impact is severe, as the script can perform any action the victim is authorized to execute within the WordPress dashboard, such as creating new administrative users, modifying plugin settings, or exfiltrating sensitive data stored in the browser's local storage or cookies (e.g., session tokens).\nThis XSS vulnerability persists across versions 1.13.21 and below, as these iterations lack the necessary input handling routines required to strip or neutralize hazardous HTML tags and JavaScript attributes effectively."
}
CVE-2026-97250: Unauthenticated XSS in Geo Mashup (HIGH Severity, CVSS: 7.1) | Sceawere