plugin

Ultimate Maps By Supsystic Vulnerabilities

7 known security issues reported for the Ultimate Maps By Supsystic WordPress plugin. Most recent disclosed Aug 18, 2026.

3 high 4 medium

Running Ultimate Maps By Supsystic on your site? Check whether your installed version is affected.

Scan your site free

Ultimate Maps by Supsystic < 1.5.0 - Unauthenticated PHP Object Injection

high

The Ultimate Maps by Supsystic plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 1.5.0. This is due to deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain...

CVSS:
8.1
Affected:
up to 1.5.0
Fixed in:
1.5.0
Disclosed:
Aug 18, 2026

CVE-2026-73376 on NVD →

Ultimate Maps by Supsystic < 1.5.0 - Unauthenticated Stored Cross-Site Scripting

high

The Ultimate Maps by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to 1.5.0. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a use...

CVSS:
7.2
Affected:
up to 1.5.0
Fixed in:
1.5.0
Disclosed:
Aug 18, 2026

CVE-2026-73375 on NVD →

Ultimate Maps by Supsystic < 1.5.0 - Missing Authorization

medium

The Ultimate Maps by Supsystic plugin for WordPress is vulnerable to unauthorized access in all versions up to 1.5.0. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.5.0
Fixed in:
1.5.0
Disclosed:
Aug 18, 2026

CVE-2026-73377 on NVD →

Ultimate Maps by Supsystic <= 1.2.16 - Cross-Site Request Forgery

medium

The Ultimate Maps by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.16. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request grante...

CVSS:
4.3
Affected:
up to 1.2.16
Fixed in:
1.2.17
Disclosed:
Apr 5, 2024

CVE-2024-31271 on NVD →

Ultimate Maps by Supsystic <= 1.2.15 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Ultimate Maps by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,...

CVSS:
4.4
Affected:
up to 1.2.15
Fixed in:
1.2.16
Disclosed:
Jan 12, 2024

CVE-2023-6732 on NVD →

Ultimate Maps by Supsystic <= 1.2.4 - Reflected Cross-Site scripting

medium

The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 1.2.4
Fixed in:
1.2.5
Disclosed:
Apr 19, 2021

CVE-2021-24274 on NVD →

Ultimate Maps by Supsystic <= 1.1.16 - Authenticated SQL Injection

high

The Ultimate Maps by Supsystic plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated-level attackers to append additi...

CVSS:
7.2
Affected:
up to 1.1.17
Fixed in:
1.1.17
Disclosed:
Feb 8, 2021

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database