VYPR
Medium severity6.5NVD Advisory· Published Sep 22, 2025· Updated Apr 28, 2026

CVE-2025-58265

CVE-2025-58265

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stonehenge Creations Events Manager – OpenStreetMaps stonehenge-em-osm allows Stored XSS.This issue affects Events Manager – OpenStreetMaps: from n/a through <= 4.2.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS vulnerability in WordPress Events Manager – OpenStreetMaps plugin up to 4.2.1 allows attackers to inject malicious scripts via improper input neutralization.

Vulnerability

Description A Stored Cross-Site Scripting (XSS) vulnerability exists in the Stonehenge Creations Events Manager – OpenStreetMaps plugin (stonehenge-em-osm) for WordPress, affecting versions from n/a through 4.2.1. The issue stems from improper neutralization of user input during web page generation, allowing arbitrary JavaScript to be stored and executed [1].

Exploitation

Requirements Exploitation requires a user with certain privileges (e.g., contributor or higher) to inject malicious payloads. However, successful execution of the stored script requires another user—such as an administrator or visitor—to interact with a crafted page or link. This user interaction is necessary for the attack to succeed [1].

Impact

An attacker can inject malicious scripts that execute when victims visit the affected site, enabling redirections, advertisement injection, or other HTML-based attacks. This can lead to session hijacking, defacement, or credential theft [1].

Mitigation

As an immediate action, users should update the plugin to a patched version if available. If updating is not possible, consider disabling the plugin or seeking assistance from a hosting provider or web developer. This vulnerability is known to be used in mass-exploit campaigns targeting WordPress sites [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.