plugin

Geo Mashup Vulnerabilities

29 known security issues reported for the Geo Mashup WordPress plugin. Most recent disclosed Aug 7, 2026.

8 high 11 medium

Running Geo Mashup on your site? Check whether your installed version is affected.

Scan your site free

Geo Mashup <= 1.13.18 - Unauthenticated Local File Inclusion

high

The Geo Mashup plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.13.18. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access control...

CVSS:
8.1
Affected:
up to 1.13.18
Fixed in:
1.13.19
Disclosed:
Aug 7, 2026

CVE-2026-66450 on NVD →

Geo Mashup <= 1.13.18 - Unauthenticated Stored Cross-Site Scripting

high

The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.13.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...

CVSS:
7.2
Affected:
up to 1.13.18
Fixed in:
1.13.19
Disclosed:
Aug 7, 2026

CVE-2026-66449 on NVD →

Geo Mashup <= 1.13.19 - Authenticated (Subscriber+) SQL Injection

medium

The Geo Mashup plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.13.19 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and abov...

CVSS:
6.5
Affected:
up to 1.13.19
Fixed in:
1.13.20
Disclosed:
Jun 3, 2026

CVE-2026-48967 on NVD →

Geo Mashup <= 1.13.19 - Missing Authorization to Unauthenticated Plugin Settings Disclosure via 'geo_mashup_content' Parameter

medium

The Geo Mashup plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.13.19. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to expose sensitive plugin configuration data, in...

CVSS:
5.3
Affected:
up to 1.13.19
Fixed in:
1.13.20
Disclosed:
May 27, 2026

CVE-2026-7552 on NVD →

Geo Mashup <= 1.13.19 - Unauthenticated Stored Cross-Site Scripting

high

The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.13.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...

CVSS:
7.2
Affected:
up to 1.13.19
Fixed in:
1.13.20
Disclosed:
May 26, 2026

CVE-2026-42734 on NVD →

Geo Mashup <= 1.13.18 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.13.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages tha...

CVSS:
6.4
Affected:
up to 1.13.18
Fixed in:
1.13.19
Disclosed:
May 26, 2026

CVE-2026-27427 on NVD →

Geo Mashup <= 1.13.19 - Authenticated (Subscriber+) SQL Injection via 'geo_mashup_null_fields' Parameter

medium

The Geo Mashup plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geo_mashup_null_fields' parameter in all versions up to, and including, 1.13.19 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible fo...

CVSS:
6.5
Affected:
up to 1.13.19
Fixed in:
1.13.20
Disclosed:
May 1, 2026

CVE-2026-6457 on NVD →

Geo Mashup <= 1.13.18 - Unauthenticated Time-Based SQL Injection via 'map_post_type' Parameter

high

The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'map_post_type' parameter in all versions up to, and including, 1.13.18. This is due to the `SearchResults` hook explicitly calling `stripslashes_deep($_POST)` which removes WordPress magic quotes protection, followed by the unsanitiz...

CVSS:
7.5
Affected:
up to 1.13.18
Fixed in:
1.13.19
Disclosed:
May 1, 2026

CVE-2026-4061 on NVD →

Geo Mashup <= 1.13.18 - Unauthenticated Time-Based SQL Injection via 'object_ids' Parameter

high

The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'object_ids' and 'exclude_object_ids' parameters in all versions up to, and including, 1.13.18. This is due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. The `es...

CVSS:
7.5
Affected:
up to 1.13.18
Fixed in:
1.13.19
Disclosed:
May 1, 2026

CVE-2026-4062 on NVD →

Geo Mashup <= 1.13.18 - Unauthenticated Time-Based SQL Injection via 'sort' Parameter

high

The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.18. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The `esc_sql()` function is applied but...

CVSS:
7.5
Affected:
up to 1.13.18
Fixed in:
1.13.19
Disclosed:
May 1, 2026

CVE-2026-4060 on NVD →

Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter

medium

Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

CVSS:
6.1
Affected:
up to 1.13.15
Fixed in:
1.13.16
Disclosed:
Apr 30, 2026

CVE-2024-13362 on NVD →

Geo Mashup <= 1.13.17 - Unauthenticated SQL Injection via 'sort' Parameter

high

The Geo Mashup plugin for WordPress is vulnerable to SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attacker...

CVSS:
7.5
Affected:
up to 1.13.17
Fixed in:
1.13.18
Disclosed:
Feb 24, 2026

CVE-2026-2416 on NVD →

Geo Mashup <= 1.13.16 - Unauthenticated Local File Inclusion

high

The Geo Mashup plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.13.16. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access con...

CVSS:
8.1
Affected:
up to 1.13.16
Fixed in:
1.13.17
Disclosed:
Jul 25, 2025

CVE-2025-48293 on NVD →

Geo Mashup [geo-mashup] < 1.13.6

unknown

[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....

Affected:
up to 1.13.6
Fixed in:
1.13.6
Disclosed:
Oct 16, 2024

CVE-2022-4974 on NVD →

Geo Mashup [geo-mashup] < 1.13.14

unknown

[en] The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's geo_mashup_visible_posts_list shortcode in all versions up to, and including, 1.13.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated at...

Affected:
up to 1.13.14
Fixed in:
1.13.14
Disclosed:
Oct 1, 2024

CVE-2024-8990 on NVD →

Geo Mashup <= 1.13.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via geo_mashup_visible_posts_list Shortcode

medium

The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's geo_mashup_visible_posts_list shortcode in all versions up to, and including, 1.13.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke...

CVSS:
6.4
Affected:
up to 1.13.13
Fixed in:
1.13.14
Disclosed:
Sep 30, 2024

CVE-2024-8990 on NVD →

Geo Mashup [geo-mashup] < 1.13.13

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup allows Stored XSS.This issue affects Geo Mashup: from n/a through 1.13.12.

Affected:
up to 1.13.13
Fixed in:
1.13.13
Disclosed:
Sep 17, 2024

CVE-2024-44008 on NVD →

Geo Mashup <= 1.13.12 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.13.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages...

CVSS:
6.5
Affected:
up to 1.13.12
Fixed in:
1.13.13
Disclosed:
Sep 16, 2024

CVE-2024-44008 on NVD →

Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get

medium

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
1.9.1 – 1.13.11
Fixed in:
1.13.12
Disclosed:
Jul 18, 2023

CVE-2023-33999 on NVD →

Freemius SDK <= 2.4.2 - Missing Authorization Checks

medium

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

CVSS:
6.3
Affected:
up to 1.13.6
Fixed in:
1.13.6
Disclosed:
Mar 4, 2022

CVE-2022-4974 on NVD →

Geo Mashup [geo-mashup] < 1.13.6

unknown

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

Affected:
up to 1.13.6
Fixed in:
1.13.6
Disclosed:
Mar 4, 2022

Geo Mashup [geo-mashup] < 1.13.6

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress Geo Mashup plugin (versions <= 1.13.5).

Affected:
up to 1.13.6
Fixed in:
1.13.6
Disclosed:
Feb 28, 2022

Geo Mashup [geo-mashup] < 1.13.6

unknown

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Geo Mashup plugin (versions <= 1.13.5).

Affected:
up to 1.13.6
Fixed in:
1.13.6
Disclosed:
Feb 28, 2022

Geo Mashup - < 1.10.4 - Cross-Site Scripting

medium

The Geo Mashup plugin before 1.10.4 for WordPress has insufficient sanitization of post editor and other user input.

CVSS:
6.4
Affected:
up to 1.10.4
Fixed in:
1.10.4
Disclosed:
Jul 16, 2018

CVE-2018-14071 on NVD →

Geo Mashup [geo-mashup] < 1.10.4

unknown

[en] The Geo Mashup plugin before 1.10.4 for WordPress has insufficient sanitization of post editor and other user input.

Affected:
up to 1.10.4
Fixed in:
1.10.4
Disclosed:
Jul 16, 2018

CVE-2018-14071 on NVD →

Geo Mashup [geo-mashup] < 1.8.3

unknown

[en] Cross-site scripting (XSS) vulnerability in the geo search widget in the Geo Mashup plugin before 1.8.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the search key.

Affected:
up to 1.8.3
Fixed in:
1.8.3
Disclosed:
Feb 2, 2015

CVE-2015-1383 on NVD →

Geo Mashup < 1.8.3 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the geo search widget in the Geo Mashup plugin before 1.8.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the search key.

CVSS:
6.1
Affected:
up to 1.8.3
Fixed in:
1.8.3
Disclosed:
Jan 27, 2015

CVE-2015-1383 on NVD →

Geo Mashup [geo-mashup] < 1.13.12

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.13.12
Fixed in:
1.13.12

CVE-2023-33999 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database