CVE-2024-13362: 100plugins Open User Map
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected products
- 100plugins Open User Map: up to and including 1.4.0
- 5starplugins Dynamic Copyright Year: up to and including 1.0.4
- 5starplugins Easy Age Verify: up to and including 1.8.5
- 5starplugins Featured Images In Rss For Mailchimp & More: up to and including 1.6.3
- 5starplugins Marijuana Age Verify: up to and including 1.5.5
- Afthemes Wp Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars: up to and including 3.8.3
- Bensibley Independent Analytics: up to and including 2.9.7
- Blackandwhitedigital Treepress – Easy Family Trees & Ancestor Profiles: up to and including 3.0.6
- Blockspare Blockspare — News, Magazine And Blog Addons For Gutenberg Block Editor: up to and including 3.2.6
- Bouncingsprout Ultimeter: up to and including 3.0.5
- Bplugins Advanced Scrollbar – Custom Scrollbar Styling And Behavior: up to and including 1.1.3
- Bplugins Bblocks – Essential Gutenberg Blocks & Patterns Collection: up to and including 1.9.8
- Bplugins HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player: up to and including 2.2.27
- Bplugins PDF Poster – Display PDF Files With Custom Viewer: up to and including 2.2.0
- Cleverplugins Security Ninja – WordPress Security & Firewall: up to and including 5.222
- Codesavory Knowledge Base Documentation & Wiki Plugin – Basepress Docs: up to and including 2.16.3.3
- Cyberhobo Geo Mashup: up to and including 1.13.15
- Cyclonecode Custom PHP Settings: up to and including 2.3.1
- Damian-Gora Justified Gallery: up to and including 1.9.0
- Dashlabsltd Yasr – Yet Another Star Rating Plugin For WordPress: up to and including 3.4.12
- Davidanderson Internal Link Juicer: Seo Auto Linker For WordPress: up to and including 2.24.6
- Elespare Elespare – News, Magazine And Blog Addons For Elementor: up to and including 3.3.2
- Elliotvs Coupon Affiliates – Affiliate Plugin For Woocommerce: up to and including 5.17.2
- Enweby Full Screen Background: up to and including 2.0.2
- Essekia Tablesome Table – Contact Form DB – Wpforms, CF7, Gravity, Forminator, Fluent: up to and including 1.1.13
- and 106 more
Published 2026-05-01. Last modified 2026-06-17.