The Geo Mashup plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.13.19. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to expose sensitive plugin configuration data, including Google Maps API keys and GeoNames service credentials, to unauthenticated attackers.
Metrics
Affected Vendors & Products
References
History
Thu, 28 May 2026 07:30:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-28T06:45:40.722Z
Reserved: 2026-04-30T19:04:25.632Z
Link: CVE-2026-7552
No data.
Status : Received
Published: 2026-05-28T08:16:36.730
Modified: 2026-05-28T08:16:36.730
Link: CVE-2026-7552
No data.
OpenCVE Enrichment
Updated: 2026-05-28T08:30:12Z