Stored Cross-Site Scripting in OpenStreetMap Plugin for WordPress
CVE-2026-4429
6.4MEDIUM
What is CVE-2026-4429?
The OpenStreetMap plugin for WordPress is exposed to Stored Cross-Site Scripting vulnerabilities through the 'marker_name' and 'file_color_list' attributes of the [osm_map_v3] shortcode. This security flaw arises from inadequate input sanitization and lack of output escaping, allowing authenticated attackers with Contributor-level access to inject malicious scripts into web pages. These scripts execute whenever a user accesses affected pages, potentially compromising user data and site integrity.
Affected Version(s)
OSM β OpenStreetMap 0 <= 6.1.15