Impact
Improper neutralization of user input during web page generation allows attackers to inject malicious JavaScript into stored content rendered by the Travelers’ Map plugin. This stored XSS flaw, identified as CWE‑79, can potentially lead to session hijacking, defacement, or delivery of additional malware to site visitors, but these specific outcomes are inferred from the nature of stored XSS and are not explicitly claimed in the CVE description. The impact therefore involves potential compromise of confidentiality, integrity, and availability.
Affected Systems
The vulnerability impacts Camille V’s Travelers’ Map plugin for WordPress installations that use version 2.3.2 or earlier. Any instance that has stored map content without proper input sanitization is susceptible until the plugin is updated beyond the affected release.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. An EPSS score of less than 1% suggests a low overall exploitation probability, and the flaw is not listed in CISA KEV. Attackers can exploit the flaw by submitting malicious content through the plugin’s administrative interface, a vector inferred from the stored‑XSS nature of the issue. Successful exploitation would insert client‑side scripts into webpages served to regular visitors, potentially allowing credential theft or other malicious actions, but these specific outcomes are inferred from the behavior of stored XSS and are not explicitly documented in the CVE description.
OpenCVE Enrichment