CVE-2026-33559
Published
CVSS v3
N/A
CVSS v2
N/A
Affected
1
PROJECT
Description
WordPress Plugin "OpenStreetMap" provided by MiKa contains a cross-site scripting vulnerability. On the site with the affected version of the plugin enabled, a logged-in user with a page-creating/editing privilege can embed some malicious script with a crafted HTTP request. When a victim user accesses this page, the script may be executed in the user's web browser.
<p>Add a map with a marker in less than 100 seconds:Add a map with marker in less than 100 sec:</p>
<span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/GDoiXO1SfJ0?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span>
<p>If you want detailed information about the OSM plugin, visit these pages:</p>
<ul>
<li>Homepage: <a href="https://wp-osm-plugin.hyumika.com/" title="OSM-plugin" rel="nofollow ugc">WP-OSM-Plugin</a></li>
<li>Forum: <a href="https://wp-osm-plugin.hyumika.com/survey/" title="OSM-plugin feedback / feature request EN|DE" rel="nofollow ugc">EN|DE</a></li>
<li>Bluesky: <a href="https://bsky.app/profile/mika-official.bsky.social" title="@mika-official.bsky.social" rel="nofollow ugc">@mika-official.bsky.social</a></li>
</ul>
<p>Features of the WP OSM plugin:</p>
<ul>
<li>OpenStreetMap, HOT, OpenSeaMap, OpenTopoMap, BaseMap (AT), Stamen in posts/pages</li>
<li>Integration in post / page / widget</li>
<li>HTML Popup Marker</li>
<li>GPX and KML (including upload in the Media Library)</li>
<li>Map with geo-tagged posts/pages as linked marker</li>
<li>Map with autogenerated track by geo-tagged posts / pages</li>
<li>HTML meta tags for geo-tagged posts/pages</li>
<li>Uses the OpenLayers library</li>
<li>SSL connection (HTTPS)</li>
</ul>
<p>Languages – thanks to:</p>
<ul>
<li>English</li>
<li>Deutsch</li>
<li>Japanese [by Sykane]</li>
<li>French [by Tounoki and Marc]</li>
<li>Russian [by Вячеслав Стренадко/Vyacheslav Strenadko]</li>
<li>Italian [by Andrea Giacomelli]</li>
<li>Spanish [by Colegota]</li>
<li>Romanian [by Sorin Pop]</li>
<li>
<p>Swedish [by Olle Zettergren]</p>
</li>
<li>
<p><a href="http://openlayers.org" rel="nofollow ugc">OpenLayers</a>: Open Source JavaScript, released under the 2-clause BSD</p>
</li>
</ul>
<p>IMPORTANT:<br />
The WordPress Plugin Review Team requires an opt-in feature for attribution display according to the <a href="https://developer.wordpress.org/plugins/wordpress-org/detailed-plugin-guidelines/#10-plugins-may-not-embed-external-links-or-credits-on-the-public-site-without-explicitly-asking-the-user%e2%80%99s-permission" rel="nofollow ugc">WordPress Plugin Guidelines</a>. Please enable the checkbox “Display attribution (credit) in the map.” in the WP OSM plugin shortcode generator, or add attribution manually to your map. Otherwise, this may violate map or data licenses, for example <a href="https://www.openstreetmap.org/copyright" rel="nofollow ugc">OpenStreetMap</a>.</p>
<p>This plugin enables GPX and KML upload!</p>
<p>Licenses of the maps:<br />
* OpenStreetMap: <a href="https://www.openstreetmap.org/copyright" rel="nofollow ugc">OpenStreetMap License</a><br />
* OpenTopoMap: <a href="https://opentopomap.org/about" rel="nofollow ugc">OpenTopoMap License</a><br />
* Stamen Maps: <a href="http://maps.stamen.com" rel="nofollow ugc">Stamen License</a><br />
* BaseMap: <a href="http://basemap.at" rel="nofollow ugc">BaseMap License</a><br />
* Thunderforest (API key): <a href="http://www.thunderforest.com/terms/" rel="nofollow ugc">Thunderforest License</a><br />
* Others: Depends on the map you are including – check it before including it!</p>