ZeroHour

CVE-2026-84818

large

Unauthenticated Cross-Site Scripting (XSS) in Open User Map WordPress Plugin

CVSS 3.1
7.1 high
EPSS
<1%p4
Published
()
Modified
AI analysis

CVE-2026-84818 is an unauthenticated cross-site scripting flaw (CWE-79) in the Open User Map WordPress plugin, affecting all versions up to and including 1.4.50. The plugin is designed to let visitors submit map markers without logging in, and this flaw allows unauthenticated requests to carry crafted JavaScript that executes in the browser of users who view the injected content, such as site visitors or administrators reviewing submitted markers (the exact injection point is not detailed in the disclosure). A successful attack could let the attacker run arbitrary JavaScript in victims' browsers, potentially hijacking sessions, performing actions as another user or administrator, or redirecting visitors, consistent with the 7.1 'high' CVSS score with scope changed and low confidentiality, integrity, and availability impact. Any WordPress site running Open User Map version 1.4.50 or earlier is affected. There are no signs of exploitation so far: EPSS estimates a 0.1% probability of exploitation in the next 30 days (4th percentile), the bug is not in the CISA KEV catalog, and no public proof-of-concept is known.

What to do: Update Open User Map to the latest patched release (any version newer than 1.4.50) as soon as possible. Until updated, consider temporarily disabling the plugin or limiting/removing public marker submission if the feature is not needed, and review submitted markers, site pages, and access logs for injected scripts or suspicious unauthenticated POST requests to the plugin's submission endpoints.

Affected
Open User Map (WordPress plugin)<= 1.4.50 (all versions through 1.4.50)
Estimated exposure
large≈10,000+ WordPress sites (plugin lists 10,000+ active installs) — Based on the plugin's wordpress.org active-install count of 10,000+, with the caveat that only sites actually accepting or displaying public marker submissions are fully exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.