Junglewise Threat Intelligence

CVE-2026-66445: 100plugins Open User Map contributor XSS

CVE-2026-66445 · Severity: medium · CVSS 6.5 · Published 2026-07-27

Technologies: 100plugins Open User Map. Vendors: 100plugins.

Executive brief

Open User Map is a WordPress plugin that allows users to add locations to a map on a website. A security vulnerability in this plugin allows users with 'Contributor' level access to inject malicious scripts into the site. If an administrator or another visitor views the affected page, these scripts could redirect users to malicious websites, display unauthorized advertisements, or steal session information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the Open User Map plugin for WordPress (versions 1.4.46 and below) due to improper neutralization of input during web page generation (CWE-79). The flaw allows an authenticated attacker with 'Contributor' level privileges to inject arbitrary JavaScript into the application. The exploit requires a victim (typically an administrator) to interact with the malicious content or visit a crafted page where the script is executed in the context of their browser session. This can lead to unauthorized actions or data theft. The issue is resolved in version 1.4.47.

Affected products

  • 100plugins Open User Map <= 1.4.46

Timeline

  • 2026-07-22: disclosed: Reported by TurboNexic via Patchstack
  • 2026-07-27: advisory: NVD and Patchstack advisory published
  • 2026-07-27: patched: Fixed in version 1.4.47

References

Related threats