WordPress security by component
Open User Map
Plugin description
Open User Map is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 6.5.
Plugin slug:
open-user-mapLatest vulnerability
CVE-2026-66445: Open User Map contributor input permits cross-site scripting
Open User Map through 1.4.46 lets a Contributor supply attacker-controlled input that reaches a browser-executable output context without adequate neutralization. The payload can execute in the site's origin when another user views the crafted output. The Patchstack CNA record does not disclose whether the payload is reflected or stored, or identify the endpoint, field, parameter or rendering function.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-66445
Open User Map contributor input permits cross-site scripting
Open User Map through 1.4.46 lets a Contributor supply attacker-controlled input that reaches a browser-executable output context without adequate neutralization. The payload can execute in the site's origin when another user views the crafted output. The Patchstack CNA record does not disclose whether the payload is reflected or stored, or identify the endpoint, field, parameter or rendering function.
|
1.4.47 |
CVE6.5
NVDPending
|
| Jul 24, 2026 |
CVE-2026-15755
Open User Map shortcode coordinates permit stored script execution
Open User Map through 1.4.45 lets a Contributor store attacker-controlled lat, long and zoom attributes in an [open-user-map] shortcode, including in a post submitted only for review. render_block_map() passes those attributes through partial-map-init.php without enforcing numeric coordinate values, and partial-map-render.php inserts them into JavaScript map variables. The stored script executes when an administrator previews the pending post or another visitor opens the rendered page.
|
1.4.46 |
CVE6.4
NVDPending
|
| Feb 20, 2026 |
CVE-2025-68002
Open User Map: Filesystem traversal
Open User Map is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Sep 22, 2025 |
CVE-2025-57953
Open User Map: Cross-site scripting
Open User Map is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Oct 18, 2023 |
CVE-2023-45056
Open User Map: Cross-site scripting
Open User Map is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|