CVE-2025-57952: WordPress Maps for WP Plugin <= 1.2.5 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icopydoc Maps for WP allows Stored XSS. This issue affects Maps for WP: from n/a through 1.2.5.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icopydoc Maps for WP maps-for-wp allows Stored XSS.This issue affects Maps for WP: from n/a through <= 1.2.5.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57952?
CVE-2025-57952 is classified as a critical cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-57952?
To fix CVE-2025-57952, update the Maps for WP plugin to version 1.2.6 or later.
What type of vulnerability is CVE-2025-57952?
CVE-2025-57952 is an improper neutralization of input during web page generation, leading to stored cross-site scripting.
Which versions of Maps for WP are affected by CVE-2025-57952?
CVE-2025-57952 affects Maps for WP versions up to and including 1.2.5.
Who is impacted by CVE-2025-57952?
Users of the Maps for WP plugin on WordPress sites are impacted by CVE-2025-57952.