← WordPress Vulnerabilities
WordPress security by component

Open User Map

Open User Map is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 6.5.

Plugin slug: open-user-map

CVE-2026-66445: Open User Map contributor input permits cross-site scripting

Open User Map through 1.4.46 lets a Contributor supply attacker-controlled input that reaches a browser-executable output context without adequate neutralization. The payload can execute in the site's origin when another user views the crafted output. The Patchstack CNA record does not disclose whether the payload is reflected or stored, or identify the endpoint, field, parameter or rendering function.

PublishedJul 27, 2026
Known safe version1.4.47
Safe version
Jul 27, 2026 CVE-2026-66445
Open User Map contributor input permits cross-site scripting
Open User Map through 1.4.46 lets a Contributor supply attacker-controlled input that reaches a browser-executable output context without adequate neutralization. The payload can execute in the site's origin when another user views the crafted output. The Patchstack CNA record does not disclose whether the payload is reflected or stored, or identify the endpoint, field, parameter or rendering function.
1.4.47
CVE6.5
NVDPending
Jul 24, 2026 CVE-2026-15755
Open User Map shortcode coordinates permit stored script execution
Open User Map through 1.4.45 lets a Contributor store attacker-controlled lat, long and zoom attributes in an [open-user-map] shortcode, including in a post submitted only for review. render_block_map() passes those attributes through partial-map-init.php without enforcing numeric coordinate values, and partial-map-render.php inserts them into JavaScript map variables. The stored script executes when an administrator previews the pending post or another visitor opens the rendered page.
1.4.46
CVE6.4
NVDPending
Feb 20, 2026 CVE-2025-68002
Open User Map: Filesystem traversal
Open User Map is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE6.5
NVDPending
Sep 22, 2025 CVE-2025-57953
Open User Map: Cross-site scripting
Open User Map is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Oct 18, 2023 CVE-2023-45056
Open User Map: Cross-site scripting
Open User Map is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8