CVE-2026-84818
largeUnauthenticated Cross-Site Scripting (XSS) in Open User Map WordPress Plugin
CVE-2026-84818 is an unauthenticated cross-site scripting flaw (CWE-79) in the Open User Map WordPress plugin, affecting all versions up to and including 1.4.50. The plugin is designed to let visitors submit map markers without logging in, and this flaw allows unauthenticated requests to carry crafted JavaScript that executes in the browser of users who view the injected content, such as site visitors or administrators reviewing submitted markers (the exact injection point is not detailed in the disclosure). A successful attack could let the attacker run arbitrary JavaScript in victims' browsers, potentially hijacking sessions, performing actions as another user or administrator, or redirecting visitors, consistent with the 7.1 'high' CVSS score with scope changed and low confidentiality, integrity, and availability impact. Any WordPress site running Open User Map version 1.4.50 or earlier is affected. There are no signs of exploitation so far: EPSS estimates a 0.1% probability of exploitation in the next 30 days (4th percentile), the bug is not in the CISA KEV catalog, and no public proof-of-concept is known.
What to do: Update Open User Map to the latest patched release (any version newer than 1.4.50) as soon as possible. Until updated, consider temporarily disabling the plugin or limiting/removing public marker submission if the feature is not needed, and review submitted markers, site pages, and access logs for injected scripts or suspicious unauthenticated POST requests to the plugin's submission endpoints.
| Open User Map (WordPress plugin) | <= 1.4.50 (all versions through 1.4.50) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.