Description
WordPress Plugin "OpenStreetMap" provided by MiKa contains a cross-site scripting vulnerability. On the site with the affected version of the plugin enabled, a logged-in user with a page-creating/editing privilege can embed some malicious script with a crafted HTTP request. When a victim user accesses this page, the script may be executed in the user's web browser.
Published: 2026-03-27
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-Site Scripting that can execute arbitrary scripts in victims’ browsers
Action: Patch Immediately
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 28 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Mar 2026 09:30:00 +0000

Type Values Removed Values Added
Title XSS Vulnerability in WordPress OpenStreetMap Plugin Allows Script Injection

Fri, 27 Mar 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Mika
Mika openstreetmap
Wordpress
Wordpress wordpress
Vendors & Products Mika
Mika openstreetmap
Wordpress
Wordpress wordpress

Fri, 27 Mar 2026 05:30:00 +0000

Type Values Removed Values Added
Description WordPress Plugin "OpenStreetMap" provided by MiKa contains a cross-site scripting vulnerability. On the site with the affected version of the plugin enabled, a logged-in user with a page-creating/editing privilege can embed some malicious script with a crafted HTTP request. When a victim user accesses this page, the script may be executed in the user's web browser.
Weaknesses CWE-79
References
Metrics cvssV3_0

{'score': 5.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Mika Openstreetmap
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-03-27T19:39:20.609Z

Reserved: 2026-03-23T05:27:00.138Z

Link: CVE-2026-33559

cve-icon Vulnrichment

Updated: 2026-03-27T19:30:42.473Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-27T06:16:39.160

Modified: 2026-03-30T13:26:29.793

Link: CVE-2026-33559

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-27T09:22:17Z

Weaknesses