PatchSiren cyber security CVE debrief
CVE-2026-39674 Manoj Kumar CVE debrief
A vulnerability was found in MK Google Directions plugin, classified as Cross-site Scripting (XSS). The issue affects MK Google Directions: from n/a through <= 3.1.1. The CVE record was published on 2026-04-08T09:16:38.957Z and has not been modified since. This vulnerability has a MEDIUM severity score and can be exploited through DOM-Based XSS. Users and administrators should review their deployments for potential exposure and verify the version of the plugin. The vulnerability is caused by Improper Neutralization of Input During Web Page Generation. Affected product context requires review of MK Google Directions plugin deployments. The CVSS score is 6.5 and the severity is MEDIUM.
- Vendor
- Manoj Kumar
- Product
- MK Google Directions
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Users of MK Google Directions plugin, operators, platform administrators, vulnerability management teams, and security teams should be aware of this vulnerability and take necessary actions to protect their systems. They should review their deployments for potential exposure, verify the version of the plugin, and apply patches or updates provided by the vendor. Additionally, they should implement compensating controls such as web application firewalls and monitor systems for suspicious activity.
Technical summary
The vulnerability is caused by Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting (XSS). The CVSS score is 6.5 and the severity is MEDIUM. The vulnerability can be exploited through DOM-Based XSS. Affected product context requires review of MK Google Directions plugin deployments. The vulnerability affects users who have installed the plugin and have not updated to a version beyond 3.1.1. The plugin's functionality and user base should be reviewed to understand potential impact.
Defensive priority
Medium priority should be given to this vulnerability as it has a MEDIUM severity score and can be exploited through DOM-Based XSS. Defenders should focus on verifying affected product deployments, reviewing official advisories, and applying patches or updates provided by the vendor.
Recommended defensive actions
- Inventory and verify the version of MK Google Directions plugin
- Apply patches or updates provided by the vendor
- Implement compensating controls such as web application firewalls
- Monitor systems for suspicious activity
- Consider exception tracking and retesting
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-04-08T09:16:38.957Z and has not been modified since. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD details. Defenders should verify affected product deployments and review official advisories. The vulnerability's impact on the plugin's users and the potential for exploitation should be assessed. Limited source detail is available; defenders should exercise caution and verify information through official channels.
Official resources
-
CVE-2026-39674 CVE record
CVE.org
-
CVE-2026-39674 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:38.957Z and has not been modified since.