PT-2026-34307 · WordPress · Posts Map

Nail Majdeddine

·

Published

2026-04-22

·

Updated

2026-05-01

·

CVE-2026-6236

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Posts map plugin for WordPress versions prior to 0.1.4
Description Insufficient input sanitization and output escaping on user supplied attributes allow authenticated attackers with contributor-level access and above to inject arbitrary web scripts. This occurs via the 'name' shortcode attribute, resulting in scripts that execute whenever a user accesses an injected page. Stored Cross-Site Scripting is a flaw where a malicious script is permanently stored on the target server.
Recommendations Update the plugin to a version later than 0.1.3.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6236

Affected Products

Posts Map