PatchSiren

bozdoz CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM bozdoz CVE published 2026-04-08

CVE-2026-39646

A Stored XSS vulnerability was found in the Leaflet Map plugin for WordPress. This issue, tracked as CVE-2026-39646, allows an attacker to inject malicious scripts into web pages. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. The vulnerability affects the Leaflet Map plugin for WordPress, versions from n/a through 3.4.4. An attacker with low privileges can exploit this vu [truncated]