ZeroHour

CVE-2026-81770

moderate

Unauthenticated XSS in Interactive Geo Maps WordPress plugin (≤ 1.6.30)

CVSS 3.1
7.1 high
EPSS
<1%p8
Published
()
Modified
AI analysis

CVE-2026-81770 is an unauthenticated cross-site scripting (XSS) flaw in the Interactive Geo Maps WordPress plugin affecting all versions up to and including 1.6.30. Because no authentication is required, an unauthenticated attacker can send a crafted request to a vulnerable site, and the injected script executes when a victim — such as a logged-in administrator or another visitor — loads the attacker-controlled link or response. Successful exploitation allows arbitrary JavaScript to run in the victim's browser, and the CVSS scope change indicates the impact extends into other parts of the site, meaning the attacker could act within the victim's authenticated session (e.g., steal cookies or perform actions as that user). Any WordPress site running Interactive Geo Maps 1.6.30 or older is affected. There is currently no public proof of concept, no entry in CISA's KEV, and with an EPSS of 0.2% (8th percentile), no exploitation in the wild is known.

What to do: Update Interactive Geo Maps to a release newer than 1.6.30 as soon as a fixed version is published (check the plugin's changelog for the patched release); if no fixed version is available yet, consider temporarily deactivating the plugin on exposed sites. Because the flaw requires no authentication, monitor access logs for suspicious crafted requests targeting the plugin's pages or endpoints in the meantime.

Affected
Interactive Geo Maps (WordPress plugin) Interactive Geo Maps<= 1.6.30
Estimated exposure
moderate≈10,000–30,000 WordPress sites (free plugin shows roughly 10,000+ active installs) — WordPress.org lists the free Interactive Geo Maps plugin at roughly 10,000+ active installations, making the plugin's install base the best available proxy for the number of exposed sites, with premium deployments adding a smaller…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.