Executive brief
The Extensions for Leaflet Map plugin for WordPress, which adds advanced mapping features like elevation charts to websites, is vulnerable to a security flaw. Authenticated users with at least 'Contributor' permissions can inject malicious scripts into pages via a specific map feature. These scripts will then execute in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on user-supplied attributes within the 'elevation-track' shortcode. An authenticated attacker with Contributor-level access or higher can exploit this by injecting arbitrary web scripts into a post or page. These scripts are stored on the server and execute in the context of a user's browser session whenever they visit the compromised page. The vulnerability is present in all versions up to and including 4.14 and was addressed in version 4.15.
Affected products
- hupe13 Extensions for Leaflet Map 0 - 4.14
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory
- 2026-04-08: patched: Fixed in version 4.15
References
- https://plugins.trac.wordpress.org/browser/extensions-leaflet-map/tags/4.11/php/functions.php
- https://plugins.trac.wordpress.org/browser/extensions-leaflet-map/tags/4.11/php/multielevation.php
- https://plugins.trac.wordpress.org/browser/extensions-leaflet-map/tags/4.15/php/functions.php?rev=3500851
- https://plugins.trac.wordpress.org/browser/extensions-leaflet-map/tags/4.15/php/multielevation.php?rev=3500851
- https://wordpress.org/plugins/extensions-leaflet-map
- https://www.wordfence.com/threat-intel/vulnerabilities/id/7749c45a-f956-4df6-98d0-5ec0db95185e?source=cve