Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mashi Simple Map No Api simple-map-no-api allows Stored XSS.This issue affects Simple Map No Api: from n/a through <= 1.9.
Published: 2025-04-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Simple Map No Api plugin for WordPress contains a stored cross‑site scripting flaw that arises from improper neutralization of user input during web page generation. An attacker who injects malicious JavaScript into input that the plugin accepts can have that script served to any browser that renders the affected page. The consequence is that the attacker can steal session cookies, deface content, or exfiltrate data from the victim’s browser environment. The weakness is classified as CWE-79.

Affected Systems

Vulnerable versions include all releases of Mashi’s Simple Map No Api plugin up to and including version 1.9. This applies to WordPress installations that have the plugin installed and activated.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity risk. The EPSS score of < 1% suggests that the likelihood of current exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an unauthenticated attacker submitting malicious data through a form or URL that the plugin stores for display; a victim visiting that page then receives and executes the injected script. Exploitation requires the plugin to be present and enabled, and the attacker benefits most when users have not applied proper privilege separation or input sanitization. The moderate severity and low exploitation probability still warrant prompt remediation to avoid potential credential theft or account takeover.

Generated by OpenCVE AI on May 1, 2026 at 01:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the patched version of the Simple Map No Api plugin (any release newer than 1.9).
  • If an update cannot be performed immediately, disable or uninstall the plugin to eliminate exposure.
  • Ensure all other WordPress plugins and theme code perform proper input validation and escaping for content that is rendered to users, following CWE‑79 mitigation guidelines.

Generated by OpenCVE AI on May 1, 2026 at 01:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9146 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mashi Simple Map No Api allows Stored XSS. This issue affects Simple Map No Api: from n/a through 1.9.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mashi Simple Map No Api allows Stored XSS. This issue affects Simple Map No Api: from n/a through 1.9. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mashi Simple Map No Api simple-map-no-api allows Stored XSS.This issue affects Simple Map No Api: from n/a through <= 1.9.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mashi Simple Map No Api allows Stored XSS. This issue affects Simple Map No Api: from n/a through 1.9.
Title WordPress Simple Map No Api plugin <= 1.9 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:15.255Z

Reserved: 2025-04-01T13:21:29.404Z

Link: CVE-2025-31890

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:32.113

Modified: 2026-04-23T15:28:29.743

Link: CVE-2025-31890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T01:45:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')