CVE-2024-8991

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's osm_map and osm_map_v3 shortcodes in all versions up to, and including, 6.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<p>Add a map with a marker in less than 100 seconds:Add a map with marker in less than 100 sec:</p> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/GDoiXO1SfJ0?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <p>If you want detailed information about the OSM plugin, visit these pages:</p> <ul> <li>Homepage: <a href="https://wp-osm-plugin.hyumika.com/" title="OSM-plugin" rel="nofollow ugc">WP-OSM-Plugin</a></li> <li>Forum: <a href="https://wp-osm-plugin.hyumika.com/survey/" title="OSM-plugin feedback / feature request EN|DE" rel="nofollow ugc">EN|DE</a></li> <li>Bluesky: <a href="https://bsky.app/profile/mika-official.bsky.social" title="@mika-official.bsky.social" rel="nofollow ugc">@mika-official.bsky.social</a></li> </ul> <p>Features of the WP OSM plugin:</p> <ul> <li>OpenStreetMap, HOT, OpenSeaMap, OpenTopoMap, BaseMap (AT), Stamen in posts/pages</li> <li>Integration in post / page / widget</li> <li>HTML Popup Marker</li> <li>GPX and KML (including upload in the Media Library)</li> <li>Map with geo-tagged posts/pages as linked marker</li> <li>Map with autogenerated track by geo-tagged posts / pages</li> <li>HTML meta tags for geo-tagged posts/pages</li> <li>Uses the OpenLayers library</li> <li>SSL connection (HTTPS)</li> </ul> <p>Languages &#8211; thanks to:</p> <ul> <li>English</li> <li>Deutsch</li> <li>Japanese [by Sykane]</li> <li>French [by Tounoki and Marc]</li> <li>Russian [by Вячеслав Стренадко/Vyacheslav Strenadko]</li> <li>Italian [by Andrea Giacomelli]</li> <li>Spanish [by Colegota]</li> <li>Romanian [by Sorin Pop]</li> <li> <p>Swedish [by Olle Zettergren]</p> </li> <li> <p><a href="http://openlayers.org" rel="nofollow ugc">OpenLayers</a>: Open Source JavaScript, released under the 2-clause BSD</p> </li> </ul> <p>IMPORTANT:<br /> The WordPress Plugin Review Team requires an opt-in feature for attribution display according to the <a href="https://developer.wordpress.org/plugins/wordpress-org/detailed-plugin-guidelines/#10-plugins-may-not-embed-external-links-or-credits-on-the-public-site-without-explicitly-asking-the-user%e2%80%99s-permission" rel="nofollow ugc">WordPress Plugin Guidelines</a>. Please enable the checkbox &#8220;Display attribution (credit) in the map.&#8221; in the WP OSM plugin shortcode generator, or add attribution manually to your map. Otherwise, this may violate map or data licenses, for example <a href="https://www.openstreetmap.org/copyright" rel="nofollow ugc">OpenStreetMap</a>.</p> <p>This plugin enables GPX and KML upload!</p> <p>Licenses of the maps:<br /> * OpenStreetMap: <a href="https://www.openstreetmap.org/copyright" rel="nofollow ugc">OpenStreetMap License</a><br /> * OpenTopoMap: <a href="https://opentopomap.org/about" rel="nofollow ugc">OpenTopoMap License</a><br /> * Stamen Maps: <a href="http://maps.stamen.com" rel="nofollow ugc">Stamen License</a><br /> * BaseMap: <a href="http://basemap.at" rel="nofollow ugc">BaseMap License</a><br /> * Thunderforest (API key): <a href="http://www.thunderforest.com/terms/" rel="nofollow ugc">Thunderforest License</a><br /> * Others: Depends on the map you are including &#8211; check it before including it!</p>
WordPress Plugin DirectoryWordPress Plugin Directory
697K