Executive brief
The Leaflet Map plugin for WordPress, which allows users to embed interactive maps into their websites, is vulnerable to a security flaw that allows attackers to inject malicious scripts. An attacker with basic contributor-level access can save malicious code on the site that executes when other users, such as administrators or visitors, view the affected map pages. This could lead to unauthorized actions being performed in the context of other users' sessions, such as redirecting visitors to malicious websites or stealing sensitive information.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the bozdoz Leaflet Map plugin for WordPress due to improper neutralization of user-supplied input during web page generation. The flaw allows an authenticated attacker with 'Contributor' level permissions or higher to inject arbitrary JavaScript into the site's database. This script is subsequently executed in the browser of any user who visits the page where the malicious content is rendered. Successful exploitation requires a victim to interact with the affected page. The vulnerability is addressed in version 3.4.5.
Affected products
- bozdoz Leaflet Map <= 3.4.4
Timeline
- 2026-01-16: other: Vulnerability reported by researcher Jitlada
- 2026-02-15: advisory: Initial advisory published by Patchstack
- 2026-02-15: patched: Version 3.4.5 released to address the issue
- 2026-04-08: disclosed: CVE published to NVD