Cross-Site Scripting Vulnerability in Extensions for Leaflet Map by hupe13
CVE-2025-66093
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 November 2025
What is CVE-2025-66093?
The Extensions for Leaflet Map by hupe13 has a vulnerability that allows for improper neutralization of input during web page generation, leading to potential DOM-based Cross-Site Scripting (XSS) attacks. This issue can affect users with versions up to 4.8, enabling attackers to inject malicious scripts that may compromise user data or manipulate site functionality. It is critical for users to update to protected versions to safeguard their applications.
Affected Version(s)
Extensions for Leaflet Map <= n/a