WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Open User Map – Interactive Leaflet Maps

Create custom interactive maps with free Leaflet-based styles, no Google Maps API key, frontend marker submissions, search and filters.

5Reported vulnerabilities
6.5Highest CVSS score
1.4.48Latest version
10,000+Active installs

What to do now

Update Open User Map – Interactive Leaflet Maps to 1.4.47 or later. 5 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 13, 2026 / Tested up to WordPress: 7.1 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2025-68002 Medium 6.5 0.3% 1.4.16 and earlier 1.4.17 February 16, 2026
CVE-2025-57953 Medium 6.4 0.3% 1.4.14 and earlier 1.4.15 September 22, 2025
CVE-2026-66445 Medium 6.4 0.1% 1.4.46 and earlier 1.4.47 July 27, 2026
CVE-2026-15755 Medium 6.4 0.2% 0 to 1.4.45 (inclusive) 1.4.46 July 24, 2026
CVE-2023-45056 Medium 4.4 0.3% 1.3.26 and earlier 1.3.27 October 3, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.