plugin

Leaflet Map Vulnerabilities

7 known security issues reported for the Leaflet Map WordPress plugin. Most recent disclosed Feb 15, 2026.

4 medium

Running Leaflet Map on your site? Check whether your installed version is affected.

Scan your site free

Leaflet Map <= 3.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
6.4
Affected:
up to 3.4.4
Fixed in:
3.4.5
Disclosed:
Feb 15, 2026

CVE-2026-39646 on NVD →

Leaflet Map [leaflet-map] < 3.3.1

unknown

[en] The Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level and above permissions to inject arbitrary we...

Affected:
up to 3.3.1
Fixed in:
3.3.1
Disclosed:
Oct 20, 2023

CVE-2023-5050 on NVD →

Leaflet Map <= 3.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level and above permissions to inject arbitrary web scr...

CVSS:
6.4
Affected:
up to 3.3.0
Fixed in:
3.3.1
Disclosed:
Sep 20, 2023

CVE-2023-5050 on NVD →

Leaflet Map [leaflet-map] < 3.0.0

unknown

[en] The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows attackers to make a logged in admin update the settings via a Cross-Site Request Forgery attack. This could lead to Cross-Site Scripting issues by either changing the URL of the JavaScript library be...

Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Aug 9, 2021

CVE-2021-24467 on NVD →

Leaflet Map [leaflet-map] < 3.0.0

unknown

[en] The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScript code or HTML, which could allow users with a role as low as Contributors to exploit stored XSS issues

Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Aug 2, 2021

CVE-2021-24468 on NVD →

Leaflet Map <= 2.23.3 - Contributor+ Stored Cross-Site Scripting

medium

The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScript code or HTML, which could allow users with a role as low as Contributors to exploit stored XSS issues

CVSS:
6.4
Affected:
up to 2.23.3
Fixed in:
3.0.0
Disclosed:
Jul 1, 2021

CVE-2021-24468 on NVD →

Leaflet Map < 3.0.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting

medium

The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows attackers to make a logged in admin update the settings via a Cross-Site Request Forgery attack. This could lead to Cross-Site Scripting issues by either changing the URL of the JavaScript library being u...

CVSS:
6.1
Affected:
up to 2.23.3
Fixed in:
3.0.0
Disclosed:
Jul 1, 2021

CVE-2021-24467 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database