๐Ÿ” CVE Alert

CVE-2026-33559

MEDIUM 5.4
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
5th

WordPress Plugin "OpenStreetMap" provided by MiKa contains a cross-site scripting vulnerability. On the site with the affected version of the plugin enabled, a logged-in user with a page-creating/editing privilege can embed some malicious script with a crafted HTTP request. When a victim user accesses this page, the script may be executed in the user's web browser.

Vendor mika
Product openstreetmap
Published Mar 27, 2026
Last Updated Mar 27, 2026
Stay Ahead of the Next One

Get instant alerts for mika openstreetmap

Be the first to know when new medium vulnerabilities affecting mika openstreetmap are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected Versions

MiKa / OpenStreetMap
prior to 6.1.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordpress.org: https://wordpress.org/plugins/osm/ jvn.jp: https://jvn.jp/en/jp/JVN48058823/