Impact
The flaw is a stored cross‑site scripting vulnerability that permits attackers to inject and store arbitrary JavaScript into pages rendered by the WordPress Leaflet Map plugin. The stored payload becomes part of the map content, causing browsers to execute the script when a user views the map. This can compromise the confidentiality, integrity, or availability of user data or the hosting web site by allowing malicious code to run in the victims' browsers.
Affected Systems
The vulnerability affects the WordPress Leaflet Map plugin provided by bozdoz. All versions up to and including 3.4.4 are impacted. Site administrators should verify which version of the plugin is deployed and whether any maps contain untrusted data.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through input fields or data entry points within the plugin where malicious payloads can be stored and later rendered to other visitors. Exploitation would typically require the ability to submit content to the plugin, so the risk is higher for accounts with content‑management privileges, and lower for anonymous users.
OpenCVE Enrichment