Impact
The Open User Map WordPress plugin contains a contributor cross‑site scripting flaw in versions up to 1.4.46. The vulnerability allows input that is displayed by the plugin to be rendered without proper encoding, resulting in the execution of malicious JavaScript in the context of any user who views the affected content.
Affected Systems
The flaw affects the Open User Map plugin distributed by 100plugins. All releases 1.4.46 and earlier are vulnerable; the fix is included in 1.4.47 and later releases.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is less than 1%, suggesting a very low likelihood of widespread exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves an attacker who can submit content through the plugin’s contributor interface or other input points that the plugin renders, causing arbitrary script execution when the content is displayed to site visitors.
OpenCVE Enrichment