Description
WordPress Plugin OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) is prone to a supply chain attack because of the Polyfill JavaScript library used. The ownership of the library was taken over by malicious threat actors that used the service to redirect victims to malicious websites. WordPress Plugin OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) version 1.1.2 is affected; prior versions may also be affected.
Remediation
Manually remove the use of Polyfill.io from the plugin, or disable and remove the plugin until a fix is available
References
https://sansec.io/research/polyfill-supply-chain-attack
https://plugins.svn.wordpress.org/stepbyteservice-openstreetmap/trunk/readme.txt
Related Vulnerabilities
Oracle HTTP Server CVE-2016-0671 Vulnerability (CVE-2016-0671)
WebLogic Missing Authentication for Critical Function Vulnerability (CVE-2026-60696)
WordPress Plugin EZ SQL Reports Shortcode Widget and DB Backup Multiple Vulnerabilities (4.11.33)
WordPress Plugin Classified Listing Store & Membership Cross-Site Scripting (1.4.19)