Junglewise Threat Intelligence

CVE-2026-84818: WordPress Open User Map unauthenticated cross-site scripting

CVE-2026-84818 · Severity: high · CVSS 7.1 · Published 2026-09-08

Technologies: 100plugins Open User Map. Vendors: 100plugins.

Executive brief

Open User Map is a WordPress plugin that displays user information on interactive maps. The plugin contains an unauthenticated cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into affected websites. Successful exploitation could result in visitor data theft, account hijacking, or malware distribution to site users.

Technical details

The vulnerability is a stored or reflected cross-site scripting (XSS) flaw in the Open User Map WordPress plugin versions 1.4.50 and earlier. The plugin fails to properly sanitize or validate user input before displaying it to visitors. An unauthenticated attacker can craft a malicious URL or entry that, when accessed or processed by the plugin, injects arbitrary JavaScript code. While the attack is network-accessible without authentication, the Patchstack advisory notes that user interaction (such as clicking a malicious link) is required for successful exploitation. The vulnerability was patched in version 1.4.51.

Affected products

  • 100plugins Open User Map <=1.4.50

Timeline

  • 2026-09-07: disclosed
  • 2026-09-07: patched: patched in version 1.4.51

References

Related threats