Stored Cross-Site Scripting in YaMaps Plugin for WordPress
CVE-2025-14851
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 February 2026
What is CVE-2025-14851?
The YaMaps plugin for WordPress is susceptible to stored cross-site scripting due to inadequate sanitization and output escaping of user-supplied attributes within the yamap shortcode parameters. This vulnerability permits authenticated attackers, with Contributor-level access and higher, to embed malicious web scripts into pages. These scripts execute when users access any affected page, posing a significant risk of data exposure and user compromise.
Affected Version(s)
YaMaps for WordPress Plugin 0 <= 0.6.40