ThreatPress

WordPress Vulnerabilities Database

Back

WordPress Geo Mashup plugin <= 1.10.3 - Unspecified Cross-Site Scripting (XSS) vulnerability

Product
Geo Mashup
Description
Unspecified Cross-Site Scripting (XSS) vulnerability found in WordPress Geo Mashup plugin (versions <= 1.10.3).
Solution
Update the WordPress Geo Mashup plugin to the latest available version (at least 1.10.4).
Classification
Type XSS (Cross Site Scripting)
OWASP Top 10 A3: Cross Site Scripting (XSS)
References
Plugin changelog
CVE
Name CVE-2018-14071
Versions
Affected In <= 1.10.3
Fixed In 1.10.4
Disclosure date
2018-07-18
Submitter
ThreatPress