Cross-Site Request Forgery Vulnerability in TravelMap Plugin by WordPress
CVE-2025-57960
4.3MEDIUM
What is CVE-2025-57960?
The TravelMap plugin for WordPress is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability, which permits unauthorized commands to be executed on behalf of a user without their consent. Successful exploitation allows attackers to potentially manipulate data or actions within the application while masquerading as legitimate users. This vulnerability affects versions up to 1.0.3, necessitating immediate attention from affected users to mitigate potential security risks.
Affected Version(s)
Travel Map <= 1.0.3
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nabil Irawan (Patchstack Alliance)