Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Camille V Travelers' Map travelers-map allows Stored XSS.This issue affects Travelers' Map: from n/a through <= 2.3.2.
Published: 2025-11-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of user input during web page generation allows attackers to inject malicious JavaScript into stored content rendered by the Travelers’ Map plugin. This stored XSS flaw, identified as CWE‑79, can potentially lead to session hijacking, defacement, or delivery of additional malware to site visitors, but these specific outcomes are inferred from the nature of stored XSS and are not explicitly claimed in the CVE description. The impact therefore involves potential compromise of confidentiality, integrity, and availability.

Affected Systems

The vulnerability impacts Camille V’s Travelers’ Map plugin for WordPress installations that use version 2.3.2 or earlier. Any instance that has stored map content without proper input sanitization is susceptible until the plugin is updated beyond the affected release.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. An EPSS score of less than 1% suggests a low overall exploitation probability, and the flaw is not listed in CISA KEV. Attackers can exploit the flaw by submitting malicious content through the plugin’s administrative interface, a vector inferred from the stored‑XSS nature of the issue. Successful exploitation would insert client‑side scripts into webpages served to regular visitors, potentially allowing credential theft or other malicious actions, but these specific outcomes are inferred from the behavior of stored XSS and are not explicitly documented in the CVE description.

Generated by OpenCVE AI on April 29, 2026 at 13:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Travelers’ Map plugin to version 2.3.3 or later
  • Sanitize or delete any existing map content that contains script tags or other malicious code
  • Configure a web application firewall or use CSP headers to block inline scripts if an immediate patch is not possible

Generated by OpenCVE AI on April 29, 2026 at 13:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 30 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 21 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Nov 2025 12:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Camille V Travelers' Map travelers-map allows Stored XSS.This issue affects Travelers' Map: from n/a through <= 2.3.2.
Title WordPress Travelers' Map plugin <= 2.3.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T19:07:33.519Z

Reserved: 2025-11-21T11:21:12.145Z

Link: CVE-2025-66098

cve-icon Vulnrichment

Updated: 2025-11-21T16:31:11.573Z

cve-icon NVD

Status : Deferred

Published: 2025-11-21T13:15:51.350

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-66098

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T13:45:12Z

Weaknesses