Junglewise Threat Intelligence

CVE-2026-2827: Open User Map PRO Stored XSS in oum_location_notification

CVE-2026-2827 · Severity: medium · CVSS 4.7 · Published 2026-06-11

Executive brief

The Open User Map PRO plugin for WordPress, which allows website visitors to contribute to interactive maps, contains a security flaw that allows attackers to inject malicious scripts. If an attacker successfully exploits this, they can run unauthorized code in the browsers of users who visit the affected map pages. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.

Technical details

The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'oum_location_notification' parameter. This vulnerability exists in versions up to and including 1.4.31. An unauthenticated attacker can exploit this by submitting a specially crafted request containing malicious JavaScript. When a user or administrator views the page where this data is stored and displayed, the script executes in their browser context. This is classified as a stored XSS (CWE-79) and requires some level of user interaction (viewing the page) to trigger.

Affected products

  • Open User Map Open User Map PRO up to, and including, 1.4.31

Timeline

  • 2026-06-11: advisory: NVD publication date

References