CVE-2025-58874
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in josepsitjar StoryMap wp-storymap allows DOM-Based XSS.This issue affects StoryMap: from n/a through <= 2.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
DOM-based XSS vulnerability in WordPress StoryMap plugin versions 2.1 and below allows remote attackers to inject malicious scripts via user interaction.
Vulnerability
Overview CVE-2025-58874 is a DOM-based Cross-Site Scripting (XSS) vulnerability in the WordPress StoryMap plugin, versions 2.1 and earlier. The issue stems from improper neutralization of user-supplied input during web page generation [1], enabling an attacker to inject arbitrary JavaScript into the DOM context.
Exploitation
Details Exploitation requires user interaction, such as clicking a crafted link or visiting a malicious page. Although an authenticated user with certain privileges must initiate the action, the attack can be triggered without direct network access to the target [1]. This vulnerability is commonly used in mass-exploit campaigns targeting thousands of WordPress sites, regardless of their traffic or popularity.
Impact
Successful exploitation allows an attacker to execute malicious scripts in the context of the victim's browser. This can lead to unauthorized actions such as redirecting users to phishing sites, injecting advertisements, or stealing sensitive data from the affected WordPress site [1].
Mitigation
As an immediate step, users should update the StoryMap plugin to a patched version (2.1 or above is vulnerable, so any fixed release post-2.1). If updating is not possible, contact your hosting provider or web developer for assistance. This vulnerability does not require CVSS score interpretation specific to WordPress [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.