PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39646 bozdoz CVE debrief

A Stored XSS vulnerability was found in the Leaflet Map plugin for WordPress. This issue, tracked as CVE-2026-39646, allows an attacker to inject malicious scripts into web pages. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. The vulnerability affects the Leaflet Map plugin for WordPress, versions from n/a through 3.4.4. An attacker with low privileges can exploit this vulnerability to inject malicious scripts into web pages, potentially leading to unauthorized actions or data breaches.

Vendor
bozdoz
Product
Leaflet Map
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Administrators and users of the Leaflet Map plugin for WordPress should be aware of this vulnerability, especially if they have not updated to a patched version. Affected operators, platforms, vulnerability-management, and security teams should review and address this vulnerability.

Technical summary

The CVE-2026-39646 vulnerability is caused by improper neutralization of input during web page generation, also known as Cross-site Scripting (XSS). The issue affects the Leaflet Map plugin for WordPress, versions from n/a through 3.4.4. An attacker with low privileges can exploit this vulnerability to inject malicious scripts into web pages, potentially leading to unauthorized actions or data breaches.

Defensive priority

Medium priority should be given to updating the Leaflet Map plugin to a version that addresses this vulnerability.

Recommended defensive actions

  • Update the Leaflet Map plugin to the latest version available.
  • Review and monitor user input to prevent malicious scripts from being injected.
  • Implement additional security measures such as Content Security Policy (CSP) to mitigate XSS attacks.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record was published on 2026-04-08T09:16:35.483Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Deferred. The vulnerability affects the Leaflet Map plugin for WordPress, versions from n/a through 3.4.4. The CVE-2026-39646 vulnerability is caused by improper neutralization of input during web page generation, also known as Cross-site Scripting (XSS).

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:35.483Z and has not been modified since then. The NVD entry is currently Deferred.