📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Information Technology CRITICAL 2h Global vulnerability Information Technology CRITICAL 3h Global vulnerability Software and Technology HIGH 4h Global vulnerability Software and Cloud Services CRITICAL 4h Global phishing Artificial Intelligence and Email Security HIGH 4h Global phishing Email and Communications CRITICAL 5h Global vulnerability Enterprise Software / E-commerce CRITICAL 6h Global supply_chain Software Development and Technology CRITICAL 6h Global vulnerability Information Technology HIGH 6h Global vulnerability Information Technology HIGH 7h Global vulnerability Information Technology CRITICAL 2h Global vulnerability Information Technology CRITICAL 3h Global vulnerability Software and Technology HIGH 4h Global vulnerability Software and Cloud Services CRITICAL 4h Global phishing Artificial Intelligence and Email Security HIGH 4h Global phishing Email and Communications CRITICAL 5h Global vulnerability Enterprise Software / E-commerce CRITICAL 6h Global supply_chain Software Development and Technology CRITICAL 6h Global vulnerability Information Technology HIGH 6h Global vulnerability Information Technology HIGH 7h Global vulnerability Information Technology CRITICAL 2h Global vulnerability Information Technology CRITICAL 3h Global vulnerability Software and Technology HIGH 4h Global vulnerability Software and Cloud Services CRITICAL 4h Global phishing Artificial Intelligence and Email Security HIGH 4h Global phishing Email and Communications CRITICAL 5h Global vulnerability Enterprise Software / E-commerce CRITICAL 6h Global supply_chain Software Development and Technology CRITICAL 6h Global vulnerability Information Technology HIGH 6h Global vulnerability Information Technology HIGH 7h
Vulnerabilities

CVE-2026-8907

Medium
CWE-352 — Weakness Type
Published: Jun 9, 2026  ·  Modified: Jun 10, 2026  ·  Source: NVD
CVSS v3
6.1
🔗 NVD Official
📄 Description (English)

The WP-Ultimate-Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to missing nonce validation on the process_init() function hooked to admin_init, which saves plugin settings (zoom-level, focus-lat, focus-lng, sel_places, sel_routes) via update_option() based solely on the presence of a save-setting POST parameter. Additionally, the saved values — particularly zoom-level — are stored without sanitization and later echoed into an HTML attribute (and inline JavaScript) on the settings page without escaping. This makes it possible for unauthenticated attackers to change plugin settings and inject arbitrary web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

🤖 AI Executive Summary

WP-Ultimate-Map plugin versions up to 1.1 are vulnerable to Cross-Site Request Forgery (CSRF) allowing attackers to modify plugin settings without proper nonce validation. The vulnerability also includes stored Cross-Site Scripting (XSS) through unsanitized and unescaped plugin settings that are reflected in HTML attributes and JavaScript.

📄 Description (Arabic)

يحتوي مكون WP-Ultimate-Map على ثغرة CSRF في دالة process_init() المرتبطة بـ admin_init حيث تفتقد التحقق من nonce عند حفظ إعدادات المكون. بالإضافة إلى ذلك، يتم حفظ القيم المدخلة دون تنظيف وتعكسها لاحقاً في سمات HTML وكود JavaScript دون هروب، مما يسمح بحقن نصوص برمجية عشوائية.

🤖 ملخص تنفيذي (AI)

WP-Ultimate-Map plugin versions up to 1.1 are vulnerable to Cross-Site Request Forgery (CSRF) allowing attackers to modify plugin settings without proper nonce validation. The vulnerability also includes stored Cross-Site Scripting (XSS) through unsanitized and unescaped plugin settings that are reflected in HTML attributes and JavaScript.

🤖 AI Intelligence Analysis Analyzed: Jun 9, 2026 09:17
🇸🇦 Saudi Arabia Impact Assessment
Saudi Relevance: high
🏢 Affected Saudi Sectors
government healthcare banking telecom
🎯 MITRE ATT&CK Techniques
⚖️ Saudi Risk Score (AI)
6.0
/ 10.0
🔧 Remediation Steps (English)
Update WP-Ultimate-Map plugin to version 1.2 or later immediately. Implement nonce verification on all admin forms using wp_verify_nonce(). Sanitize all user inputs with sanitize_text_field() or appropriate sanitization functions. Escape all output with esc_attr() for HTML attributes and esc_js() for JavaScript contexts. Conduct security audit of all WordPress plugins for similar vulnerabilities.
🔧 خطوات المعالجة (العربية)
قم بتحديث مكون WP-Ultimate-Map إلى الإصدار 1.2 أو أحدث فوراً. تطبيق التحقق من nonce على جميع نماذج المسؤول باستخدام wp_verify_nonce(). تنظيف جميع مدخلات المستخدم باستخدام sanitize_text_field() أو وظائف التنظيف المناسبة. الهروب من جميع المخرجات باستخدام esc_attr() لسمات HTML و esc_js() لسياقات JavaScript. إجراء تدقيق أمني لجميع مكونات WordPress للبحث عن ثغرات مماثلة.
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
5.1.1 5.1.2 5.2.1
🔵 SAMA CSF
AC-3 AC-6 SI-10
🟡 ISO 27001:2022
A.14.2.1 A.14.2.5
📊 CVSS Score
6.1
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionR — Required
ScopeC — Changed
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityN — None / Network
📋 Quick Facts
Severity Medium
CVSS Score6.1
CWECWE-352
Exploit No
Patch ✗ No
Published 2026-06-09
Source Feed nvd
🇸🇦 Saudi Risk Score
6.0
/ 10.0 — Saudi Risk
Priority: MEDIUM
🏷️ Tags
CWE-352
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.