PT-2026-64252 · WordPress · Open User Map

·

CVE-2026-15755

·

Published

2026-07-24

·

Updated

2026-07-24

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Open User Map – Interactive Leaflet Maps plugin for WordPress versions prior to 1.4.46
Description Insufficient input sanitization and output escaping allow authenticated attackers with contributor-level access and above to perform Stored Cross-Site Scripting (XSS). This occurs via shortcode attributes, enabling the injection of arbitrary web scripts into pages. These scripts execute when a user accesses the affected page. The issue can be triggered even before a post is published, as the payload executes when an administrator views a post submitted for pending review.
Recommendations Update the plugin to version 1.4.46 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15755

Affected Products

Open User Map