Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tempranova WP Mapbox GL JS Maps wp-mapbox-gl-js allows Stored XSS.This issue affects WP Mapbox GL JS Maps: from n/a through <= 3.0.1.
Published: 2025-10-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw that occurs when malicious input is not properly neutralized before being embedded in a web page generated by the WP Mapbox GL JS Maps plugin. An attacker can inject arbitrary JavaScript that will execute in the browser context of any user viewing a page that includes the compromised map, allowing session hijacking, credential theft, or defacement. The weakness (CWE‑79) satisfies the prerequisites for a stored XSS: the input is persisted and later reflected without sanitization, resulting in a breach of confidentiality and integrity for end‑users.

Affected Systems

This issue affects the WordPress WP Mapbox GL JS Maps plugin, developed by tempranova, in all releases up to and including 3.0.1. It is inferred that earlier releases are also affected because the description lists no lower bound and the core map rendering logic has not changed prior to the first patched release.

Risk and Exploitability

The plugin’s CVSS score of 6.5 indicates moderate severity while the EPSS score of less than 1% shows a very low probability that the vulnerability will be actively exploited. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector requires the attacker to supply malicious input that is stored by the plugin—either through an administrative interface or a crafted POST request—and then provoke the target site to render that data, which can be achieved by visiting a page that includes a map rendered by the plugin.

Generated by OpenCVE AI on April 29, 2026 at 23:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WP Mapbox GL JS Maps plugin to version 3.0.2 or later, which patches the stored XSS flaw.
  • If an immediate update is not possible, disable or uninstall the plugin to eliminate the risk.
  • As a temporary measure, review and sanitize any stored map configuration data, ensuring that any script tags or event handlers are stripped or properly encoded before rendering.

Generated by OpenCVE AI on April 29, 2026 at 23:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Tue, 28 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Tempranova
Tempranova wp Mapbox Gl Js Maps
Wordpress
Wordpress wordpress
Vendors & Products Tempranova
Tempranova wp Mapbox Gl Js Maps
Wordpress
Wordpress wordpress

Mon, 27 Oct 2025 02:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tempranova WP Mapbox GL JS Maps wp-mapbox-gl-js allows Stored XSS.This issue affects WP Mapbox GL JS Maps: from n/a through <= 3.0.1.
Title WordPress WP Mapbox GL JS Maps plugin <= 3.0.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Tempranova Wp Mapbox Gl Js Maps
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:06.644Z

Reserved: 2025-10-24T14:24:48.653Z

Link: CVE-2025-62942

cve-icon Vulnrichment

Updated: 2025-10-27T15:12:08.167Z

cve-icon NVD

Status : Deferred

Published: 2025-10-27T02:15:54.280

Modified: 2026-04-27T17:16:36.603

Link: CVE-2025-62942

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T23:30:22Z

Weaknesses