Waymark
Waymark has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 4 are fixed as of September 2026. Their average CVSS score is 6.3, and the most serious one scores 6.4 out of 10. 2025 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (75%). Other recurring categories include Server-Side Request Forgery (SSRF).
Every one of the 4 issues recorded for Waymark has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, most of them (2) reported by theviper17y. Waymark is installed on roughly 900 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-32487Waymark <= 1.5.2 - Authenticated (Contributor+) Server-Side Request Forgery
Read the full analysisVulnerability Records

Waymark
Author
Joe
❤️ Keep This Project Alive Through Sponsorship ❤️ Creating Maps Use the intuitive Editor to create Maps with one, or thousands of interactive Overlays. Overlays – Create Markers, Lines and Shapes with a: Title Image (Media Library or link to external image) Description (Rich text editor, HTML supported) Type (defined in Settings) Import GPX KML GeoJSON EXIF (Image location metadata) Elevation data (adds an interactive profile chart for Lines with elevation data) Meta – Add extra information to your Maps; these are customisable form inputs that allow you to add additional content to your Maps. Types – Set options to visually distinguish between Overlays (colours/icons etc.), then select it when using the Editor. Collections – Group Maps together and display multiple Maps at once. Create complex Collection hierarchies to suit your needs and associate Maps with multiple Collections. Submissions – Allow registered users, or guests to create Maps from the front-end of your site. You can control who can Submit Maps, what editor features are available and whether submissions should be approved before they are published. 🌟 GitHub 👐 WordPress 📖 Demo & Docs Displaying Maps Embed your Maps using the [Waymark] Shortcode, or link to the Map Details page. Shortcodes Display a single Map, or a Collection of Maps anywhere that Shortcodes are supported. An optional Shortcode Header displays the Map/Collection title, a link to the Map Details page and any Meta. Display a Marker defined through the Shortcode. Display a Basemap only, without any Overlays by providing centre and zoom parameters. Basemaps – Uses OpenStreetMap by default, with support for multiple raster tiled/”slippy” Basemaps. You can switch Basemaps using the Overlay Filter. Overlay Filter – Allow the user to filter which Overlays are currently visible on the Map. Export (Optionally) Let anyone Export Maps into GPX, KML and GeoJSON formats through the Shortcode Header or on the Map Details page. Works on mobile devices. Customising Built to be flexible, Waymark has lots of Settings and Types provide one place to control how Overlays (Markers/Lines/Shapes) are displayed. Marker Icons can be provided as: – Font Icons (Ionic Icons v2/Font Awesome v4) – Simple Text, or Emojis (i.e. 🏕️, 🚩, 📸). – Custom HTML (good ol’ <img src="https://example.com/icon.svg">, or a more complex structure). So you can pretty much create any kind of Icon you want. For developers: Most elements can be styled using CSS and have sensibly named waymark- classes. WordPress integration: Maps are stored using the custom post type waymark_map. Collections use the waymark_collection Taxonomy. Embed Maps using the [Waymark] Shortcode anywhere they are supported, or dynamically using the do_shortcode(["Waymark"]) function. Geographical data is stored in GeoJSON format. Types are specified using the type Property, i.e. {feature: { geometry: { type: 'Point', coordinates: [0, 0] } }, properties: { type: 'Alert', title: 'Bridge Removed!' }. Specify which GeoJSON feature properties to store when importing (Settings > Overlays > Properties). These can be automatically appended to the Overlay Description, or accessed programatically via the layer.feature.properties Object. Maps are displayed using the Leaflet JavaScript library, which is bundled with Waymark and can be extended using the waymark_loaded_callback [callback function](https://www.ogis.org/waymark-wp/advanced/using-the-global-callback-function/. Be sure to check out Map First, a minimal WordPress theme with an obsession for Maps (it’s open-source too and contains lots of comments about customisations). Waymark is free, open-source (GPL v2) and a labour of Love. I try to keep the plugin well supported, so please feel free to reach out with any issues, questions or feedback. User Examples Association Franc-Comtoise du Chemin de Compostelle – eGuide Cres & Lošinj Trail – Lošinj Trail 2025 hikingTICINO Horizontes – PT281 Iggy’s Hikes – Staze na Medvednici Il Cammino del Lago Maggiore – Le 11 tappe Merritt Mountain Bike Association – Iron Mountain The Island Walk – Island Walk Map Trekkaholic – Trekking al lago Bianco in Alpe Veglia Via Apsyrtides Zadar Archipelago – Interactive Map Zagorje Outdoor – Konjička staza broj 10 Updated 10 September 2026 Development [!NOTE] To develop locally you will need to have both Node.js and NPM installed. Grunt is used to run the build script, which compiles the JavaScript and CSS and performs some other tasks. # Clone the repository (and the Waymark JS submodule) git clone --recurse-submodules https://github.com/opengis/waymark.git # Navigate to the Waymark directory cd waymark # Install the dependencies (or pnpm/yarn install) npm install # Run the build script grunt The build script will watch for changes to the JavaScript and CSS files. Pull requests are welcome! [!IMPORTANT] Waymark JS is responsible for the Viewer and Editor and is included as a Git submodule (/waymark-js directory). View on GitHub. Dev Server A local WordPress environment is provided via wp-env. Docker must be running. npm run dev This starts WordPress at http://localhost:8888 and prints the credentials summary: ──────────────────────────────────── MySQL 127.0.0.1 root / password Admin http://localhost:8888/wp-admin admin / password ────────────────────────────────────
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C