PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39646 bozdoz CVE debrief

A Stored XSS vulnerability was found in the Leaflet Map plugin for WordPress. This issue, tracked as CVE-2026-39646, allows an attacker to inject malicious scripts into web pages. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. The vulnerability affects the Leaflet Map plugin for WordPress, versions from n/a through 3.4.4. An attacker with low privileges can exploit this vulnerability to inject malicious scripts into web pages, potentially leading to unauthorized actions or data breaches.

Vendor
bozdoz
Product
Leaflet Map
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Administrators and users of the Leaflet Map plugin for WordPress should be aware of this vulnerability, especially if they have not updated to a patched version. Affected operators, platforms, vulnerability-management, and security teams should review and address this vulnerability.

Technical summary

The CVE-2026-39646 vulnerability is caused by improper neutralization of input during web page generation, also known as Cross-site Scripting (XSS). The issue affects the Leaflet Map plugin for WordPress, versions from n/a through 3.4.4. An attacker with low privileges can exploit this vulnerability to inject malicious scripts into web pages, potentially leading to unauthorized actions or data breaches.

Defensive priority

Medium priority should be given to updating the Leaflet Map plugin to a version that addresses this vulnerability.

Recommended defensive actions

  • Update the Leaflet Map plugin to the latest version available.
  • Review and monitor user input to prevent malicious scripts from being injected.
  • Implement additional security measures such as Content Security Policy (CSP) to mitigate XSS attacks.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record was published on 2026-04-08T09:16:35.483Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Deferred. The vulnerability affects the Leaflet Map plugin for WordPress, versions from n/a through 3.4.4. The CVE-2026-39646 vulnerability is caused by improper neutralization of input during web page generation, also known as Cross-site Scripting (XSS).

Sources and references

Verified primary and authoritative sources

  • CVE-2026-39646 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-39646

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-39646 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-39646

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.