PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39674 Manoj Kumar CVE debrief

A vulnerability was found in MK Google Directions plugin, classified as Cross-site Scripting (XSS). The issue affects MK Google Directions: from n/a through <= 3.1.1. The CVE record was published on 2026-04-08T09:16:38.957Z and has not been modified since. This vulnerability has a MEDIUM severity score and can be exploited through DOM-Based XSS. Users and administrators should review their deployments for potential exposure and verify the version of the plugin. The vulnerability is caused by Improper Neutralization of Input During Web Page Generation. Affected product context requires review of MK Google Directions plugin deployments. The CVSS score is 6.5 and the severity is MEDIUM.

Vendor
Manoj Kumar
Product
MK Google Directions
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Users of MK Google Directions plugin, operators, platform administrators, vulnerability management teams, and security teams should be aware of this vulnerability and take necessary actions to protect their systems. They should review their deployments for potential exposure, verify the version of the plugin, and apply patches or updates provided by the vendor. Additionally, they should implement compensating controls such as web application firewalls and monitor systems for suspicious activity.

Technical summary

The vulnerability is caused by Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting (XSS). The CVSS score is 6.5 and the severity is MEDIUM. The vulnerability can be exploited through DOM-Based XSS. Affected product context requires review of MK Google Directions plugin deployments. The vulnerability affects users who have installed the plugin and have not updated to a version beyond 3.1.1. The plugin's functionality and user base should be reviewed to understand potential impact.

Defensive priority

Medium priority should be given to this vulnerability as it has a MEDIUM severity score and can be exploited through DOM-Based XSS. Defenders should focus on verifying affected product deployments, reviewing official advisories, and applying patches or updates provided by the vendor.

Recommended defensive actions

  • Inventory and verify the version of MK Google Directions plugin
  • Apply patches or updates provided by the vendor
  • Implement compensating controls such as web application firewalls
  • Monitor systems for suspicious activity
  • Consider exception tracking and retesting
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-04-08T09:16:38.957Z and has not been modified since. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD details. Defenders should verify affected product deployments and review official advisories. The vulnerability's impact on the plugin's users and the potential for exploitation should be assessed. Limited source detail is available; defenders should exercise caution and verify information through official channels.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:38.957Z and has not been modified since.