Executive brief
The OpenStreetMap plugin for WordPress, which allows users to embed interactive maps into posts and pages, contains a security vulnerability. An attacker with permission to create or edit posts can inject malicious scripts into a page. If another user, such as a site administrator, views that page, the script will execute in their browser, potentially allowing the attacker to perform unauthorized actions or steal session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the MiKa OpenStreetMap (OSM) plugin for WordPress due to improper neutralization of input during web page generation (CWE-79). The flaw allows an authenticated attacker with page-creating or editing privileges (typically Contributor level or higher) to embed malicious scripts via a crafted HTTP request. These scripts are then executed in the context of a victim's browser session when they navigate to the affected page. The vulnerability is addressed in version 6.1.15.
Affected products
- MiKa OpenStreetMap (OSM) prior to 6.1.15
Timeline
- 2026-03-27: disclosed
- 2026-03-27: advisory
- 2026-03-27: patched: Fixed in version 6.1.15