Cross-Site Request Forgery Vulnerability in TravelMap Plugin by WordPress
CVE-2025-57960

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2025

What is CVE-2025-57960?

The TravelMap plugin for WordPress is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability, which permits unauthorized commands to be executed on behalf of a user without their consent. Successful exploitation allows attackers to potentially manipulate data or actions within the application while masquerading as legitimate users. This vulnerability affects versions up to 1.0.3, necessitating immediate attention from affected users to mitigate potential security risks.

Affected Version(s)

Travel Map <= 1.0.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan (Patchstack Alliance)
.