Executive brief
The Extensions for Leaflet Map plugin for WordPress is vulnerable to a security flaw that allows attackers to inject malicious scripts into web pages. This plugin is used to add interactive maps to websites. If exploited, an attacker could redirect visitors to malicious sites, steal session information, or display unauthorized content, potentially damaging the website's reputation and compromising user data.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the hupe13 Extensions for Leaflet Map plugin for WordPress due to improper neutralization of user-supplied input during web page generation. The flaw allows unauthenticated attackers to inject malicious scripts into the Document Object Model (DOM) environment. Successful exploitation requires a victim to interact with a specially crafted link or page (User Interaction). Once executed, the script runs in the context of the victim's browser session, potentially allowing for session hijacking or unauthorized actions. The issue is resolved in version 5.2.
Affected products
- hupe13 Extensions for Leaflet Map <= 5.1
Timeline
- 2026-06-03: other: Vulnerability reported by researcher manop55555
- 2026-07-07: disclosed: Initial disclosure by Patchstack
- 2026-07-13: advisory: NVD publication date
- 2026-07-13: patched: Patch available in version 5.2