Description
Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive US Map interactive-us-map allows Stored XSS.This issue affects Interactive US Map: from n/a through <= 2.7.
Published: 2025-04-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated or unauthenticated attacker can craft a request that takes advantage of the plugin’s missing CSRF protection, causing the WordPress site to store an arbitrary JavaScript string in the database. When the site renders that content, the injected script runs in the browser of any visitor. This stored XSS could be used to modify site appearance, steal session cookies, redirect users, or deliver malware, thereby impacting confidentiality, integrity, and availability of the web application.

Affected Systems

The vulnerability exists in the Interactive US Map plugin for WordPress, affecting all installations running version 2.7 or earlier. Site owners who have installed the plugin and allow content entry via the map widget or related admin pages are exposed.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate severity and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. Because the vulnerability is not listed in the CISA KEV catalogue, there are no confirmed exploits yet. Attackers can feasibly exploit the flaw by hosting a malicious page that triggers the vulnerable plugin’s endpoint, with the victim’s browser submitting the crafted request. Successful exploitation requires that the victim has permission to submit content via the map widget or that the site accepts unauthenticated submissions, after which the stored script will affect all users who view the affected page.

Generated by OpenCVE AI on May 1, 2026 at 00:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Interactive US Map plugin to the latest version that contains the CSRF fix.
  • If an update is not immediately available, disable the plugin or restrict its use to trusted administrators to prevent further storage of malicious content.
  • Verify that any future configurations of the plugin enforce CSRF tokens or nonces for content submission requests to eliminate the underlying weakness.

Generated by OpenCVE AI on May 1, 2026 at 00:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10562 Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive US Map allows Stored XSS. This issue affects Interactive US Map: from n/a through 2.7.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive US Map allows Stored XSS. This issue affects Interactive US Map: from n/a through 2.7. Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive US Map interactive-us-map allows Stored XSS.This issue affects Interactive US Map: from n/a through <= 2.7.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 09 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Apr 2025 16:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive US Map allows Stored XSS. This issue affects Interactive US Map: from n/a through 2.7.
Title WordPress Interactive US Map plugin <= 2.7 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:27.159Z

Reserved: 2025-04-09T11:21:11.059Z

Link: CVE-2025-32661

cve-icon Vulnrichment

Updated: 2025-04-09T18:52:57.233Z

cve-icon NVD

Status : Deferred

Published: 2025-04-09T17:15:50.493

Modified: 2026-06-17T09:12:22.820

Link: CVE-2025-32661

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T00:15:04Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)