WPIntell

Source evidence

vulnerabilty found according to patchstack

MapGeo – Interactive Geo Maps · support · 2025-04-10T08:37:00+00:00

mixedsentiment
highseverity
0.95relevance
8replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

3 / 19 rows with source links

15.8% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

16 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
suikerspin resolved
Hello, According to patchstack the current version of the plugin (and lower versions) is vulnerable. See https://patchstack.com/database/wordpress/plugin/interactive-geo-maps/vulnerability/wordpress-interactive-geo-maps-plugin-1-6-24-reflected-cross-site-scripting-xss-vulnerability?_a_id=110 Are you planning a fix? Greetings, when there’s a security vulnerability found, usually these companies send the plugin authors at least a month before it’s made public, instructions on where the issue is and suggestions on how to fix it, so that when the issue is made public, there’s already a fixed version. We are currently awaiting additional instructions from patchstack with more information. We apologize for the delay however we are waiting also for feedback which may take a week to validate. I can confirm this from our local env . One of the vulnerability was via post_type=igmap&page=interactive-geo-maps-pricing which was fixed by freemius-sdk v2.11.0 and we patched in v1.6.23 . The other one was in any tab, where user could inject encoded JavaScript snippets or images with links and trick users to click. We have fixed this in v1.6.25 by sanitizing url params before using them Thanks for the updates, look forward to seeing a new version we can download soon to fix. WordFence has also flagged a security vulnerability. https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/interactive-geo-maps/interactive-geo-maps-1624-reflected-cross-site-scripting I have some sites with the Pro version and some with the free. The free version can only be updated to 1.6.18, although I can uninstall and then download 1.6.24, this does not include the security update. Will there be a rollout for the free version? This reply was modified 1 year, 2 months ago by Rich Ambrose . This reply was modified 1 year, 2 months ago by Rich Ambrose . Reason: Improved the question This reply was modified 1 year, 2 months ago by Yui . Hello, just following up on this – it is marked as RESOLVED but doesn’t appear to be? At least, I don’t see a patched version available for download anywhere? Hello Everyone, we rolled out a new patched version just yesterday Hello, when will the version be online? On my end, I don’t have anything at all. Thanks. New version does not seem online despite this showing as resolved and statements of “we rolled out a new patched version” which is now 2 days ago. Can we ask if developers if this can be fetched manually elsewhere (your own site?) if it’s not here?

Comments

8 shown
MapGeo 2025-04-12T08:41:00+00:00

Greetings, when there’s a security vulnerability found, usually these companies send the plugin authors at least a month before it’s made public, instructions on where the issue is and suggestions on how to fix it, so that when the issue is made public, there’s already a fixed version. We are currently awaiting additional instructions from patchstack with more information. We apologize for the delay however we are waiting also for feedback which may take a week to validate.

MapGeo 2025-04-14T00:02:00+00:00

I can confirm this from our local env . One of the vulnerability was via post_type=igmap&page=interactive-geo-maps-pricing which was fixed by freemius-sdk v2.11.0 and we patched in v1.6.23 . The other one was in any tab, where user could inject encoded JavaScript snippets or images with links and trick users to click. We have fixed this in v1.6.25 by sanitizing url params before using them

Exo 2025-04-14T07:09:00+00:00

Thanks for the updates, look forward to seeing a new version we can download soon to fix.

Rich Ambrose 2025-04-17T10:27:00+00:00

WordFence has also flagged a security vulnerability. https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/interactive-geo-maps/interactive-geo-maps-1624-reflected-cross-site-scripting I have some sites with the Pro version and some with the free. The free version can only be updated to 1.6.18, although I can uninstall and then download 1.6.24, this does not include the security update. Will there be a rollout for the free version? This reply was modified 1 year, 2 months ago by Rich Ambrose . This reply was modified 1 year, 2 months ago by Rich Ambrose . Reason: Improved the question This reply was modified 1 year, 2 months ago by Yui .

kalvinkingsleymint 2025-04-18T16:30:00+00:00

Hello, just following up on this – it is marked as RESOLVED but doesn’t appear to be? At least, I don’t see a patched version available for download anywhere?

MapGeo 2025-04-18T17:27:00+00:00

Hello Everyone, we rolled out a new patched version just yesterday

lohanelbt 2025-04-20T08:04:00+00:00

Hello, when will the version be online? On my end, I don’t have anything at all. Thanks.

Exo 2025-04-20T16:50:00+00:00

New version does not seem online despite this showing as resolved and statements of “we rolled out a new patched version” which is now 2 days ago. Can we ask if developers if this can be fetched manually elsewhere (your own site?) if it’s not here?