Skip to content

Known CVE

Geo Mashup <= 1.13.18 - SQL Injection

Geo Mashup WordPress plugin <= 1.13.18 is vulnerable to time-based SQL injection via the sort parameter. The issue exists because the sort value is insufficiently sanitized in render-map.php/template tag code paths.

CVE-2026-4060

High2026CVSS 7.5CWE-89

cve2026 · wordpress · wp · wp-plugin · sqli · geo-mashup

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website