Stored Cross-Site Scripting Vulnerability in LS Google Map Router Plugin for WordPress
CVE-2025-13850
What is CVE-2025-13850?
The LS Google Map Router plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) via the 'map_type' parameter across all versions prior to 1.1.0. Insufficient input sanitization and output escaping allow authenticated users, with Contributor-level access or higher, to insert harmful web scripts. These scripts will execute whenever a page containing the injected code is accessed, posing significant risks to site security and user data integrity. This vulnerability highlights the importance of proper validation and sanitation of user inputs to prevent such attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
LS Google Map Router * <= 1.1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved