PatchSiren cyber security CVE debrief
CVE-2026-39646 bozdoz CVE debrief
A Stored XSS vulnerability was found in the Leaflet Map plugin for WordPress. This issue, tracked as CVE-2026-39646, allows an attacker to inject malicious scripts into web pages. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. The vulnerability affects the Leaflet Map plugin for WordPress, versions from n/a through 3.4.4. An attacker with low privileges can exploit this vulnerability to inject malicious scripts into web pages, potentially leading to unauthorized actions or data breaches.
- Vendor
- bozdoz
- Product
- Leaflet Map
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Administrators and users of the Leaflet Map plugin for WordPress should be aware of this vulnerability, especially if they have not updated to a patched version. Affected operators, platforms, vulnerability-management, and security teams should review and address this vulnerability.
Technical summary
The CVE-2026-39646 vulnerability is caused by improper neutralization of input during web page generation, also known as Cross-site Scripting (XSS). The issue affects the Leaflet Map plugin for WordPress, versions from n/a through 3.4.4. An attacker with low privileges can exploit this vulnerability to inject malicious scripts into web pages, potentially leading to unauthorized actions or data breaches.
Defensive priority
Medium priority should be given to updating the Leaflet Map plugin to a version that addresses this vulnerability.
Recommended defensive actions
- Update the Leaflet Map plugin to the latest version available.
- Review and monitor user input to prevent malicious scripts from being injected.
- Implement additional security measures such as Content Security Policy (CSP) to mitigate XSS attacks.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record was published on 2026-04-08T09:16:35.483Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Deferred. The vulnerability affects the Leaflet Map plugin for WordPress, versions from n/a through 3.4.4. The CVE-2026-39646 vulnerability is caused by improper neutralization of input during web page generation, also known as Cross-site Scripting (XSS).
Official resources
-
CVE-2026-39646 CVE record
CVE.org
-
CVE-2026-39646 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:35.483Z and has not been modified since then. The NVD entry is currently Deferred.