OSM – OpenStreetMap
OSM – OpenStreetMap has 9 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2026; all 9 are fixed as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 9.9 out of 10. Severity breakdown: 1 critical and 1 high. 2024 was the busiest year with 4 disclosures.
The most common weakness is Cross-Site Scripting, behind 6 of the records (67%). Other recurring categories include Cross-Site Request Forgery (CSRF), Missing Authorization.
Every one of the 9 issues recorded for OSM – OpenStreetMap has a vendor fix available, so running the current release closes all known holes.
8 independent researchers contributed these findings, most of them (2) reported by Krzysztof Zając. OSM – OpenStreetMap is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2024-3604OSM – OpenStreetMap <= 6.0.3 - Authenticated (Contributor+) SQL Injection
Read the full analysisVulnerability Records

OSM – OpenStreetMap
Author
MiKa
Add a map with a marker in less than 100 seconds:Add a map with marker in less than 100 sec: If you want detailed information about the OSM plugin, visit these pages: Homepage: WP-OSM-Plugin Forum: EN|DE Bluesky: @mika-official.bsky.social Features of the WP OSM plugin: OpenStreetMap, HOT, OpenSeaMap, OpenTopoMap, BaseMap (AT), Stamen in posts/pages Integration in post / page / widget HTML Popup Marker GPX and KML (including upload in the Media Library) Map with geo-tagged posts/pages as linked marker Map with autogenerated track by geo-tagged posts / pages HTML meta tags for geo-tagged posts/pages Uses the OpenLayers library SSL connection (HTTPS) Languages – thanks to: English Deutsch Japanese [by Sykane] French [by Tounoki and Marc] Russian [by Вячеслав Стренадко/Vyacheslav Strenadko] Italian [by Andrea Giacomelli] Spanish [by Colegota] Romanian [by Sorin Pop] Swedish [by Olle Zettergren] OpenLayers: Open Source JavaScript, released under the 2-clause BSD IMPORTANT: The WordPress Plugin Review Team requires an opt-in feature for attribution display according to the WordPress Plugin Guidelines. Please enable the checkbox “Display attribution (credit) in the map.” in the WP OSM plugin shortcode generator, or add attribution manually to your map. Otherwise, this may violate map or data licenses, for example OpenStreetMap. This plugin enables GPX and KML upload! Licenses of the maps: * OpenStreetMap: OpenStreetMap License * OpenTopoMap: OpenTopoMap License * Stamen Maps: Stamen License * BaseMap: BaseMap License * Thunderforest (API key): Thunderforest License * Others: Depends on the map you are including – check it before including it!
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C