Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stephanemartinw Mapbox for WP Advanced mapbox-for-wp-advanced allows Reflected XSS.This issue affects Mapbox for WP Advanced: from n/a through <= 1.0.0.
Published: 2025-01-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of user input that allows reflected cross‑site scripting in the Mapbox for WP Advanced plugin. By injecting malicious script payloads into crafted requests, an attacker can execute arbitrary JavaScript in the browser of any visitor to the site, leading to credential theft, session hijacking, or defacement. The impact is on confidentiality, integrity, and availability of user accounts and site content.

Affected Systems

The affected product is the WordPress Mapbox for WP Advanced plugin developed by stephanemartinw. Versions from the initial release up to and including 1.0.0 are susceptible. The vulnerability is present in any WordPress installation that has this plugin and has not yet been updated to a newer release.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity. The EPSS score of less than 1% suggests a low likelihood of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector, inferred from the description, is a reflected XSS that can be triggered by an attacker sending a crafted URL or form input to the plugin’s exposed endpoints. Acceptance of arbitrary user input without proper sanitization allows the payload to be reflected back in the HTTP response, executing in the victim’s browser. No authentication or administrative privileges are required to exploit this flaw, so the risk is accessible to any attacker able to target a website using the vulnerable plugin.

Generated by OpenCVE AI on May 1, 2026 at 19:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mapbox for WP Advanced to a release newer than 1.0.0 or remove the plugin entirely.
  • If an upgrade is not feasible, restrict the plugin’s public endpoints by configuring a web application firewall or by adding server‑side input validation to reject untrusted payloads.
  • Implement a Content‑Security‑Policy that limits executable scripts to trusted sources, providing a secondary defense against reflected XSS attacks.

Generated by OpenCVE AI on May 1, 2026 at 19:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-2983 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Mapbox for WP Advanced allows Reflected XSS. This issue affects Mapbox for WP Advanced: from n/a through 1.0.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Mapbox for WP Advanced allows Reflected XSS. This issue affects Mapbox for WP Advanced: from n/a through 1.0.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stephanemartinw Mapbox for WP Advanced mapbox-for-wp-advanced allows Reflected XSS.This issue affects Mapbox for WP Advanced: from n/a through <= 1.0.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 22 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jan 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Mapbox for WP Advanced allows Reflected XSS. This issue affects Mapbox for WP Advanced: from n/a through 1.0.0.
Title WordPress Mapbox for WP Advanced Plugin <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:07.046Z

Reserved: 2025-01-07T21:04:56.181Z

Link: CVE-2025-22772

cve-icon Vulnrichment

Updated: 2025-01-22T19:22:30.383Z

cve-icon NVD

Status : Deferred

Published: 2025-01-22T15:15:14.990

Modified: 2026-06-17T08:49:56.910

Link: CVE-2025-22772

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T19:30:23Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')