Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arsh91 Pin Locations on Map pin-locations-on-map allows Reflected XSS.This issue affects Pin Locations on Map: from n/a through <= 1.0.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an instance of Improper Neutralization of Input During Web Page Generation (CWE‑79). When a user supplies malicious input through a form or URL parameter, the Pin Locations on Map plugin echoes that input into the generated page without proper encoding. The attacker’s script then executes in the victim’s browser, enabling theft of session cookies or execution of arbitrary actions on behalf of the victim. The flaw directly impacts confidentiality, integrity, and potentially authentication of the affected WordPress site.

Affected Systems

WordPress sites that have the arsh91 Pin Locations on Map plugin installed at any version up through 1.0. These installations process user‑provided data without adequate sanitization, making the entire site vulnerable as far as the plugin’s front‑end components are concerned.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑to‑high severity vulnerability. The EPSS score is below 1 %, showing that widespread exploitation is currently unlikely, yet the flaw remains actionable. The vulnerability is not listed in the CISA KEV catalog, but its potential to compromise user sessions remains. Attackers would typically craft a URL containing malicious payloads and convince a victim to visit it, thereby exploiting the reflected XSS vector.

Generated by OpenCVE AI on May 2, 2026 at 03:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Pin Locations on Map plugin to a version that contains the XSS fix (at least 1.1 or later).
  • If an upgrade is not immediately possible, deactivate or remove the plugin from the WordPress installation to eliminate the vulnerable code path.
  • Consider restricting plugin usage to authenticated administrators only to reduce exposure to unauthenticated users.

Generated by OpenCVE AI on May 2, 2026 at 03:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5690 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Pin Locations on Map allows Reflected XSS. This issue affects Pin Locations on Map: from n/a through 1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Pin Locations on Map allows Reflected XSS. This issue affects Pin Locations on Map: from n/a through 1.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arsh91 Pin Locations on Map pin-locations-on-map allows Reflected XSS.This issue affects Pin Locations on Map: from n/a through <= 1.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Pin Locations on Map allows Reflected XSS. This issue affects Pin Locations on Map: from n/a through 1.0.
Title WordPress Pin Locations on Map plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:13.718Z

Reserved: 2025-01-16T11:26:37.847Z

Link: CVE-2025-23584

cve-icon Vulnrichment

Updated: 2025-03-04T21:47:54.888Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:43.010

Modified: 2026-06-17T08:55:34.070

Link: CVE-2025-23584

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T04:00:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')