CVE-2026-33559

Published
View on NVD ↗
CVSS v3
N/A
CVSS v2
N/A
Affected
1
PROJECT

Description

WordPress Plugin "OpenStreetMap" provided by MiKa contains a cross-site scripting vulnerability. On the site with the affected version of the plugin enabled, a logged-in user with a page-creating/editing privilege can embed some malicious script with a crafted HTTP request. When a victim user accesses this page, the script may be executed in the user's web browser.

<p>Add a map with a marker in less than 100 seconds:Add a map with marker in less than 100 sec:</p> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/GDoiXO1SfJ0?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <p>If you want detailed information about the OSM plugin, visit these pages:</p> <ul> <li>Homepage: <a href="https://wp-osm-plugin.hyumika.com/" title="OSM-plugin" rel="nofollow ugc">WP-OSM-Plugin</a></li> <li>Forum: <a href="https://wp-osm-plugin.hyumika.com/survey/" title="OSM-plugin feedback / feature request EN|DE" rel="nofollow ugc">EN|DE</a></li> <li>Bluesky: <a href="https://bsky.app/profile/mika-official.bsky.social" title="@mika-official.bsky.social" rel="nofollow ugc">@mika-official.bsky.social</a></li> </ul> <p>Features of the WP OSM plugin:</p> <ul> <li>OpenStreetMap, HOT, OpenSeaMap, OpenTopoMap, BaseMap (AT), Stamen in posts/pages</li> <li>Integration in post / page / widget</li> <li>HTML Popup Marker</li> <li>GPX and KML (including upload in the Media Library)</li> <li>Map with geo-tagged posts/pages as linked marker</li> <li>Map with autogenerated track by geo-tagged posts / pages</li> <li>HTML meta tags for geo-tagged posts/pages</li> <li>Uses the OpenLayers library</li> <li>SSL connection (HTTPS)</li> </ul> <p>Languages &#8211; thanks to:</p> <ul> <li>English</li> <li>Deutsch</li> <li>Japanese [by Sykane]</li> <li>French [by Tounoki and Marc]</li> <li>Russian [by Вячеслав Стренадко/Vyacheslav Strenadko]</li> <li>Italian [by Andrea Giacomelli]</li> <li>Spanish [by Colegota]</li> <li>Romanian [by Sorin Pop]</li> <li> <p>Swedish [by Olle Zettergren]</p> </li> <li> <p><a href="http://openlayers.org" rel="nofollow ugc">OpenLayers</a>: Open Source JavaScript, released under the 2-clause BSD</p> </li> </ul> <p>IMPORTANT:<br /> The WordPress Plugin Review Team requires an opt-in feature for attribution display according to the <a href="https://developer.wordpress.org/plugins/wordpress-org/detailed-plugin-guidelines/#10-plugins-may-not-embed-external-links-or-credits-on-the-public-site-without-explicitly-asking-the-user%e2%80%99s-permission" rel="nofollow ugc">WordPress Plugin Guidelines</a>. Please enable the checkbox &#8220;Display attribution (credit) in the map.&#8221; in the WP OSM plugin shortcode generator, or add attribution manually to your map. Otherwise, this may violate map or data licenses, for example <a href="https://www.openstreetmap.org/copyright" rel="nofollow ugc">OpenStreetMap</a>.</p> <p>This plugin enables GPX and KML upload!</p> <p>Licenses of the maps:<br /> * OpenStreetMap: <a href="https://www.openstreetmap.org/copyright" rel="nofollow ugc">OpenStreetMap License</a><br /> * OpenTopoMap: <a href="https://opentopomap.org/about" rel="nofollow ugc">OpenTopoMap License</a><br /> * Stamen Maps: <a href="http://maps.stamen.com" rel="nofollow ugc">Stamen License</a><br /> * BaseMap: <a href="http://basemap.at" rel="nofollow ugc">BaseMap License</a><br /> * Thunderforest (API key): <a href="http://www.thunderforest.com/terms/" rel="nofollow ugc">Thunderforest License</a><br /> * Others: Depends on the map you are including &#8211; check it before including it!</p>
WordPress Plugin DirectoryWordPress Plugin Directory
697K