Leaflet Map <= 3.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 6.4
- Affected:
- up to 3.4.4
- Fixed in:
- 3.4.5
- Disclosed:
- Feb 15, 2026
CVE-2026-39646 on NVD →
Leaflet Map [leaflet-map] < 3.3.1
unknown
[en] The Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level and above permissions to inject arbitrary we...
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.1
- Disclosed:
- Oct 20, 2023
CVE-2023-5050 on NVD →
Leaflet Map <= 3.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level and above permissions to inject arbitrary web scr...
- CVSS:
- 6.4
- Affected:
- up to 3.3.0
- Fixed in:
- 3.3.1
- Disclosed:
- Sep 20, 2023
CVE-2023-5050 on NVD →
Leaflet Map [leaflet-map] < 3.0.0
unknown
[en] The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows attackers to make a logged in admin update the settings via a Cross-Site Request Forgery attack. This could lead to Cross-Site Scripting issues by either changing the URL of the JavaScript library be...
- Affected:
- up to 3.0.0
- Fixed in:
- 3.0.0
- Disclosed:
- Aug 9, 2021
CVE-2021-24467 on NVD →
Leaflet Map [leaflet-map] < 3.0.0
unknown
[en] The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScript code or HTML, which could allow users with a role as low as Contributors to exploit stored XSS issues
- Affected:
- up to 3.0.0
- Fixed in:
- 3.0.0
- Disclosed:
- Aug 2, 2021
CVE-2021-24468 on NVD →
Leaflet Map <= 2.23.3 - Contributor+ Stored Cross-Site Scripting
medium
The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScript code or HTML, which could allow users with a role as low as Contributors to exploit stored XSS issues
- CVSS:
- 6.4
- Affected:
- up to 2.23.3
- Fixed in:
- 3.0.0
- Disclosed:
- Jul 1, 2021
CVE-2021-24468 on NVD →
Leaflet Map < 3.0.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting
medium
The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows attackers to make a logged in admin update the settings via a Cross-Site Request Forgery attack. This could lead to Cross-Site Scripting issues by either changing the URL of the JavaScript library being u...
- CVSS:
- 6.1
- Affected:
- up to 2.23.3
- Fixed in:
- 3.0.0
- Disclosed:
- Jul 1, 2021
CVE-2021-24467 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database