Description
Cross-Site Request Forgery (CSRF) vulnerability in TravelMap Travel Map travelmap-blog allows Cross Site Request Forgery.This issue affects Travel Map: from n/a through <= 1.0.3.
Published: 2025-09-22
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Travel Map plugin contains a CSRF weakness that permits an attacker to forge requests on behalf of an authenticated user. By exploiting this flaw, an attacker could trigger the plugin to execute any actions that the logged‑in user is authorized to perform, thereby compromising the integrity of site content or plugin configuration, but it does not allow direct code execution or disclosure of secrets.

Affected Systems

WordPress sites that have the Travel Map plugin version 1.0.3 or earlier installed are affected. The plugin is bundled under the vendor TravelMap and is used in various WordPress deployments; any site running these versions faces the stated vulnerability.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate potential impact and the EPSS score of less than 1% reflects a low likelihood of widespread exploitation in the immediate future. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to persuade a legitimate user to submit a crafted request or send a malicious link to a browser session that already holds authentication cookies for the site. Without administrative access or specific user privileges, the damage remains limited to the operations that the authenticated user can perform, making the risk lower than for higher severity flaws.

Generated by OpenCVE AI on April 30, 2026 at 06:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Travel Map plugin to version 1.0.4 or later to remove the CSRF flaw.
  • If an upgrade is not immediately possible, disable the Travel Map plugin or restrict its access to trusted users only, preventing unauthenticated or outside users from triggering its endpoints.
  • Ensure that WordPress nonce tokens are enabled for all forms that interact with Travel Map, and remove any code paths that process the plugin’s actions without a valid token.

Generated by OpenCVE AI on April 30, 2026 at 06:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30688 Cross-Site Request Forgery (CSRF) vulnerability in TravelMap Travel Map allows Cross Site Request Forgery. This issue affects Travel Map: from n/a through 1.0.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in TravelMap Travel Map allows Cross Site Request Forgery. This issue affects Travel Map: from n/a through 1.0.3. Cross-Site Request Forgery (CSRF) vulnerability in TravelMap Travel Map travelmap-blog allows Cross Site Request Forgery.This issue affects Travel Map: from n/a through <= 1.0.3.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 24 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Travelmap
Travelmap travelmap
Wordpress
Wordpress wordpress
Vendors & Products Travelmap
Travelmap travelmap
Wordpress
Wordpress wordpress

Mon, 22 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in TravelMap Travel Map allows Cross Site Request Forgery. This issue affects Travel Map: from n/a through 1.0.3.
Title WordPress Travel Map Plugin <= 1.0.3 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Travelmap Travelmap
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:39.335Z

Reserved: 2025-08-22T11:36:51.669Z

Link: CVE-2025-57960

cve-icon Vulnrichment

Updated: 2025-09-24T15:19:29.206Z

cve-icon NVD

Status : Deferred

Published: 2025-09-22T19:15:54.860

Modified: 2026-04-23T15:33:08.117

Link: CVE-2025-57960

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T06:45:16Z

Weaknesses