plugin

Mappress Google Maps For Wordpress Vulnerabilities

31 known security issues reported for the Mappress Google Maps For Wordpress WordPress plugin. Most recent disclosed Jul 24, 2026.

3 high 14 medium

Running Mappress Google Maps For Wordpress on your site? Check whether your installed version is affected.

Scan your site free

MapPress – Google Maps, OpenStreetMap & Leaflet <= 2.97.6 - Unauthenticated Information Exposure

medium

The MapPress – Google Maps, OpenStreetMap & Leaflet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.97.6. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 2.97.6
Fixed in:
2.97.7
Disclosed:
Jul 24, 2026

CVE-2026-65564 on NVD →

MapPress Maps for WordPress <= 2.97.3 - Unauthenticated Stored Cross-Site Scripting

high

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.97.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever...

CVSS:
7.2
Affected:
up to 2.97.3
Fixed in:
2.97.4
Disclosed:
Jun 19, 2026

CVE-2026-56011 on NVD →

MapPress Maps for WordPress <= 2.96.6 - Unauthenticated Insecure Direct Object Reference via REST API Endpoints

medium

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.96.6. This is due to missing ownership verification in the REST API routes registered via `Mappress_Api::rest_api_init()`, where the GET `/wp-json/mapp/v1/maps/{...

CVSS:
5.3
Affected:
up to 2.96.6
Fixed in:
2.97.1
Disclosed:
Jun 5, 2026

CVE-2026-8839 on NVD →

MapPress Maps for WordPress <= 2.94.9 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.94.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...

CVSS:
4.4
Affected:
up to 2.94.9
Fixed in:
2.94.10
Disclosed:
Mar 27, 2025

CVE-2025-2162 on NVD →

MapPress Maps for WordPress <= 2.94.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.94.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web...

CVSS:
6.4
Affected:
up to 2.94.8
Fixed in:
2.94.9
Disclosed:
Mar 13, 2025

CVE-2025-2055 on NVD →

MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.94.2

unknown

[en] The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map block in all versions up to, and including, 2.94.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

Affected:
up to 2.94.2
Fixed in:
2.94.2
Disclosed:
Nov 6, 2024

CVE-2024-10715 on NVD →

MapPress Maps for WordPress <= 2.94.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Block

medium

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map block in all versions up to, and including, 2.94.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contr...

CVSS:
6.4
Affected:
up to 2.94.1
Fixed in:
2.94.2
Disclosed:
Nov 5, 2024

CVE-2024-10715 on NVD →

MapPress Maps for WordPress <= 2.92.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.92.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...

CVSS:
4.4
Affected:
up to 2.92.2
Fixed in:
2.93
Disclosed:
Sep 24, 2024

CVE-2024-8620 on NVD →

MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.88.16

unknown

[en] The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retrieve via an AJAX action is a public map, allowing unauthenticated users to read arbitrary private and draft posts.

Affected:
up to 2.88.16
Fixed in:
2.88.16
Disclosed:
Feb 12, 2024

CVE-2024-0421 on NVD →

MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.88.15

unknown

[en] The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back in the admin dashboard, allowing Contributors and above roles to perform Stored Cross-Site Scripting attacks

Affected:
up to 2.88.15
Fixed in:
2.88.15
Disclosed:
Feb 12, 2024

CVE-2024-0420 on NVD →

MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.88.17

unknown

[en] The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the width and height parameters in all versions up to, and including, 2.88.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access...

Affected:
up to 2.88.17
Fixed in:
2.88.17
Disclosed:
Jan 30, 2024

CVE-2023-7225 on NVD →

MapPress <= 2.88.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Settings

medium

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the width and height parameters in all versions up to, and including, 2.88.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and...

CVSS:
6.4
Affected:
up to 2.88.16
Fixed in:
2.88.17
Disclosed:
Jan 29, 2024

CVE-2023-7225 on NVD →

MapPress Maps for WordPress <= 2.88.14 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via map titles in all versions up to, and including, 2.88.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to injec...

CVSS:
6.4
Affected:
up to 2.88.14
Fixed in:
2.88.15
Disclosed:
Jan 17, 2024

CVE-2024-0420 on NVD →

MapPress Maps for WordPress <= 2.88.15 - Insufficient Authorization to Information Disclosure

medium

The MapPress Maps for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the mapp_get_post AJAX action in all versions up to, and including, 2.88.15. This makes it possible for unauthenticated attackers to read arbitrary private and draft posts.

CVSS:
5.3
Affected:
up to 2.88.15
Fixed in:
2.88.16
Disclosed:
Jan 17, 2024

CVE-2024-0421 on NVD →

MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.88.14

unknown

[en] The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the map title parameter in all versions up to and including 2.88.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher...

Affected:
up to 2.88.14
Fixed in:
2.88.14
Disclosed:
Jan 3, 2024

CVE-2023-6524 on NVD →

MapPress Maps for WordPress <= 2.88.13 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the map title parameter in all versions up to and including 2.88.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to in...

CVSS:
6.4
Affected:
up to 2.88.13
Fixed in:
2.88.14
Disclosed:
Jan 2, 2024

CVE-2023-6524 on NVD →

MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.85.5

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Chris Richardson MapPress Maps for WordPress mappress-google-maps-for-wordpress allows SQL Injection.This issue affects MapPress Maps for WordPress: from n/a through 2.85.4.

Affected:
up to 2.85.5
Fixed in:
2.85.5
Disclosed:
Nov 3, 2023

CVE-2023-26015 on NVD →

MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.88.5

unknown

[en] The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mappress' shortcode in versions up to, and including, 2.88.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contrib...

Affected:
up to 2.88.5
Fixed in:
2.88.5
Disclosed:
Sep 12, 2023

CVE-2023-4840 on NVD →

MapPress Maps for WordPress <= 2.88.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mappress' shortcode in versions up to, and including, 2.88.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-...

CVSS:
6.4
Affected:
up to 2.88.4
Fixed in:
2.88.5
Disclosed:
Sep 11, 2023

CVE-2023-4840 on NVD →

MapPress Maps for WordPress <= 2.85.4 - Authenticated (Contributor+) SQL Injection via get_maps

high

The MapPress Maps for WordPress plugin for WordPress is vulnerable to SQL Injection via the get_maps function in versions up to, and including, 2.85.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attac...

CVSS:
8.8
Affected:
up to 2.85.4
Fixed in:
2.85.5
Disclosed:
Apr 6, 2023

CVE-2023-26015 on NVD →

MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.73.13

unknown

[en] The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings and upload arbitrary files to the site through the "ajax_save" function. The file is written relative to the current 's stylesheet directory, and a .php file extensio...

Affected:
up to 2.73.13
Fixed in:
2.73.13
Disclosed:
Apr 4, 2022

CVE-2022-0537 on NVD →

MapPress Maps for WordPress <= 2.73.12 - Admin+ File Upload to Remote Code Execution

medium

The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings and upload arbitrary files to the site through the "ajax_save" function. The file is written relative to the current 's stylesheet directory, and a .php file extension is...

CVSS:
6
Affected:
up to 2.73.13
Fixed in:
2.73.13
Disclosed:
Mar 14, 2022

CVE-2022-0537 on NVD →

MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.73.4

unknown

[en] The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting it back in the "Bad mapid" error message, leading to a Reflected Cross-Site Scripting

Affected:
up to 2.73.4
Fixed in:
2.73.4
Disclosed:
Feb 14, 2022

CVE-2022-0208 on NVD →

MapPress Maps <= 2.73.3 - Reflected Cross-Site Scripting

medium

The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting it back in the "Bad mapid" error message, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 2.73.4
Fixed in:
2.73.4
Disclosed:
Jan 17, 2022

CVE-2022-0208 on NVD →

MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.54.6

unknown

[en] The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related to creation/retrieval/deletion of PHP template files, leading to Remote Code Execution. NOTE: this issue exists because of an incomplete fix for CVE-2020-12077.

Affected:
up to 2.54.6
Fixed in:
2.54.6
Disclosed:
May 29, 2020

CVE-2020-12675 on NVD →

MapPress Maps <= 2.54.5 - Remote Code Execution via Improper Capability Checks in AJAX Calls

high

The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related to creation/retrieval/deletion of PHP template files, leading to Remote Code Execution. NOTE: this issue exists because of an incomplete fix for CVE-2020-12077.

CVSS:
8.8
Affected:
up to 2.54.5
Fixed in:
2.54.6
Disclosed:
May 28, 2020

CVE-2020-12675 on NVD →

MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.53.9

unknown

[en] The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions with nonces (or capability checks), leading to remote code execution.

Affected:
up to 2.53.9
Fixed in:
2.53.9
Disclosed:
Apr 23, 2020

CVE-2020-12077 on NVD →

MapPress Maps for WordPress <=2.53.8 - Authenticated Map Creation/Deletion to Stored Cross-Site Scripting & Remote Code Execution

medium

The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions with nonces (or capability checks), leading to remote code execution.

CVSS:
6.5
Affected:
up to 2.53.9
Fixed in:
2.53.9
Disclosed:
Apr 1, 2020

CVE-2020-12077 on NVD →

MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.94.9

unknown
Affected:
up to 2.94.9
Fixed in:
2.94.9

CVE-2025-2055 on NVD →

MapPress Maps for WordPress [mappress-google-maps-for-wordpress] <= 2.94.10

unknown
Affected:
up to 2.94.10
Fixed in:
2.94.10

CVE-2025-2162 on NVD →

MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.93

unknown
Affected:
up to 2.93
Fixed in:
2.93

CVE-2024-8620 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database