VYPR
Medium severity6.5NVD Advisory· Published Sep 5, 2025· Updated Apr 23, 2026

CVE-2025-58874

CVE-2025-58874

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in josepsitjar StoryMap wp-storymap allows DOM-Based XSS.This issue affects StoryMap: from n/a through <= 2.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

DOM-based XSS vulnerability in WordPress StoryMap plugin versions 2.1 and below allows remote attackers to inject malicious scripts via user interaction.

Vulnerability

Overview CVE-2025-58874 is a DOM-based Cross-Site Scripting (XSS) vulnerability in the WordPress StoryMap plugin, versions 2.1 and earlier. The issue stems from improper neutralization of user-supplied input during web page generation [1], enabling an attacker to inject arbitrary JavaScript into the DOM context.

Exploitation

Details Exploitation requires user interaction, such as clicking a crafted link or visiting a malicious page. Although an authenticated user with certain privileges must initiate the action, the attack can be triggered without direct network access to the target [1]. This vulnerability is commonly used in mass-exploit campaigns targeting thousands of WordPress sites, regardless of their traffic or popularity.

Impact

Successful exploitation allows an attacker to execute malicious scripts in the context of the victim's browser. This can lead to unauthorized actions such as redirecting users to phishing sites, injecting advertisements, or stealing sensitive data from the affected WordPress site [1].

Mitigation

As an immediate step, users should update the StoryMap plugin to a patched version (2.1 or above is vulnerable, so any fixed release post-2.1). If updating is not possible, contact your hosting provider or web developer for assistance. This vulnerability does not require CVSS score interpretation specific to WordPress [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.