VYPR
High severity7.1NVD Advisory· Published May 27, 2026

CVE-2026-42734

CVE-2026-42734

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup geo-mashup allows Reflected XSS.This issue affects Geo Mashup: from n/a through <= 1.13.19.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A reflected cross-site scripting (XSS) vulnerability in the Geo Mashup plugin for WordPress (versions ≤1.13.19) allows attackers to inject arbitrary scripts via a malicious link.

Vulnerability

The Geo Mashup WordPress plugin versions 1.13.19 and earlier fail to properly neutralize user-supplied input, leading to a reflected cross-site scripting (XSS) vulnerability [1]. An attacker can inject malicious scripts into a page that will be executed in the browser of a user who visits a crafted link. The vulnerable parameters are not detailed in the available references, but the issue applies to plugin versions from n/a through 1.13.19 inclusive [1].

Exploitation

Exploitation requires user interaction: a privileged WordPress user (such as an administrator) must be tricked into clicking a specially crafted link, visiting a maliciously constructed page, or submitting a form [1]. The attacker does not need prior authentication or special network position; the attack is initiated by luring the victim to the crafted request via email, social engineering, or another website [1].

Impact

A successful attack allows the attacker to inject arbitrary HTML and JavaScript into the victim's browser session within the context of the affected WordPress site. This can be used to perform actions such as redirecting visitors to malicious sites, displaying unwanted advertisements, stealing session cookies, or executing other payloads that could compromise the site's integrity and user trust [1].

Mitigation

Patched version 1.13.20 has been released to resolve the vulnerability. The vendor advises immediate update to version 1.13.20 or later [1]. For sites that cannot immediately update, Patchstack provides a mitigation rule to block attacks until the plugin is updated [1]. No other workarounds are listed in the available references.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.