plugin

Dsgvo Leaflet Map Vulnerabilities

2 known security issues reported for the Dsgvo Leaflet Map WordPress plugin. Most recent disclosed Mar 27, 2026.

2 medium

Running Dsgvo Leaflet Map on your site? Check whether your installed version is affected.

Scan your site free

DSGVO snippet for Leaflet Map and its Extensions - Authenticated (Contributor+) Stored Cross-Site Scripting via 'unset' Attribute vulnerability

medium

Authenticated (Contributor+) Stored Cross-Site Scripting via 'unset' Attribute vulnerability

CVSS:
6.5
Affected:
up to 3.1
Fixed in:
3.4
Disclosed:
Mar 27, 2026

DSGVO snippet for Leaflet Map and its Extensions <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'unset' Attribute

medium

The DSGVO snippet for Leaflet Map and its Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `leafext-cookie-time` and `leafext-delete-cookie` shortcodes in all versions up to, and including, 3.1. This is due to insufficient input sanitization and output escaping on user supplied attri...

CVSS:
6.4
Affected:
up to 3.1
Fixed in:
3.4
Disclosed:
Mar 23, 2026

CVE-2026-4389 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database