what3words Address Field
what3words Address Field has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 5.7, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor.
Every one of the 2 issues recorded for what3words Address Field has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by Abdi Pranata. what3words Address Field is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-26768what3words Address Field <= 4.0.15 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Read the full analysisVulnerability Records

what3words Address Field
Author
what3words
Add a what3words address field to collect more accurate delivery locations from customers Reduce lost parcels, spend less time on delivery admin, and improve customer satisfaction. This address field enables you to collect and validate what3words addresses entered by your customers. They can then be passed to your delivery provider, so orders arrive in exactly the right place. what3words enables your customers to give precise delivery locations. Every 3 metre square in the world has an address made of 3 random words. Enable a what3words address field at checkout Validate what3words addresses as they are entered AutoSuggest feature helps customers enter the correct address Option to limit entry of what3words addresses to a specific country or area Save location coordinates so they’re easy to pass on to couriers and delivery partners
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C