CVE-2026-81770
moderateUnauthenticated XSS in Interactive Geo Maps WordPress plugin (≤ 1.6.30)
CVE-2026-81770 is an unauthenticated cross-site scripting (XSS) flaw in the Interactive Geo Maps WordPress plugin affecting all versions up to and including 1.6.30. Because no authentication is required, an unauthenticated attacker can send a crafted request to a vulnerable site, and the injected script executes when a victim — such as a logged-in administrator or another visitor — loads the attacker-controlled link or response. Successful exploitation allows arbitrary JavaScript to run in the victim's browser, and the CVSS scope change indicates the impact extends into other parts of the site, meaning the attacker could act within the victim's authenticated session (e.g., steal cookies or perform actions as that user). Any WordPress site running Interactive Geo Maps 1.6.30 or older is affected. There is currently no public proof of concept, no entry in CISA's KEV, and with an EPSS of 0.2% (8th percentile), no exploitation in the wild is known.
What to do: Update Interactive Geo Maps to a release newer than 1.6.30 as soon as a fixed version is published (check the plugin's changelog for the patched release); if no fixed version is available yet, consider temporarily deactivating the plugin on exposed sites. Because the flaw requires no authentication, monitor access logs for suspicious crafted requests targeting the plugin's pages or endpoints in the meantime.
| Interactive Geo Maps (WordPress plugin) Interactive Geo Maps | <= 1.6.30 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.