MapPress – Google Maps, OpenStreetMap & Leaflet <= 2.97.6 - Unauthenticated Information Exposure
medium
The MapPress – Google Maps, OpenStreetMap & Leaflet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.97.6. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 2.97.6
- Fixed in:
- 2.97.7
- Disclosed:
- Jul 24, 2026
CVE-2026-65564 on NVD →
MapPress Maps for WordPress <= 2.97.3 - Unauthenticated Stored Cross-Site Scripting
high
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.97.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever...
- CVSS:
- 7.2
- Affected:
- up to 2.97.3
- Fixed in:
- 2.97.4
- Disclosed:
- Jun 19, 2026
CVE-2026-56011 on NVD →
MapPress Maps for WordPress <= 2.96.6 - Unauthenticated Insecure Direct Object Reference via REST API Endpoints
medium
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.96.6. This is due to missing ownership verification in the REST API routes registered via `Mappress_Api::rest_api_init()`, where the GET `/wp-json/mapp/v1/maps/{...
- CVSS:
- 5.3
- Affected:
- up to 2.96.6
- Fixed in:
- 2.97.1
- Disclosed:
- Jun 5, 2026
CVE-2026-8839 on NVD →
MapPress Maps for WordPress <= 2.94.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.94.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...
- CVSS:
- 4.4
- Affected:
- up to 2.94.9
- Fixed in:
- 2.94.10
- Disclosed:
- Mar 27, 2025
CVE-2025-2162 on NVD →
MapPress Maps for WordPress <= 2.94.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.94.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web...
- CVSS:
- 6.4
- Affected:
- up to 2.94.8
- Fixed in:
- 2.94.9
- Disclosed:
- Mar 13, 2025
CVE-2025-2055 on NVD →
MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.94.2
unknown
[en] The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map block in all versions up to, and including, 2.94.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- Affected:
- up to 2.94.2
- Fixed in:
- 2.94.2
- Disclosed:
- Nov 6, 2024
CVE-2024-10715 on NVD →
MapPress Maps for WordPress <= 2.94.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Block
medium
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map block in all versions up to, and including, 2.94.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contr...
- CVSS:
- 6.4
- Affected:
- up to 2.94.1
- Fixed in:
- 2.94.2
- Disclosed:
- Nov 5, 2024
CVE-2024-10715 on NVD →
MapPress Maps for WordPress <= 2.92.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.92.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...
- CVSS:
- 4.4
- Affected:
- up to 2.92.2
- Fixed in:
- 2.93
- Disclosed:
- Sep 24, 2024
CVE-2024-8620 on NVD →
MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.88.16
unknown
[en] The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retrieve via an AJAX action is a public map, allowing unauthenticated users to read arbitrary private and draft posts.
- Affected:
- up to 2.88.16
- Fixed in:
- 2.88.16
- Disclosed:
- Feb 12, 2024
CVE-2024-0421 on NVD →
MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.88.15
unknown
[en] The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back in the admin dashboard, allowing Contributors and above roles to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 2.88.15
- Fixed in:
- 2.88.15
- Disclosed:
- Feb 12, 2024
CVE-2024-0420 on NVD →
MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.88.17
unknown
[en] The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the width and height parameters in all versions up to, and including, 2.88.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access...
- Affected:
- up to 2.88.17
- Fixed in:
- 2.88.17
- Disclosed:
- Jan 30, 2024
CVE-2023-7225 on NVD →
MapPress <= 2.88.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Settings
medium
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the width and height parameters in all versions up to, and including, 2.88.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and...
- CVSS:
- 6.4
- Affected:
- up to 2.88.16
- Fixed in:
- 2.88.17
- Disclosed:
- Jan 29, 2024
CVE-2023-7225 on NVD →
MapPress Maps for WordPress <= 2.88.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via map titles in all versions up to, and including, 2.88.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to injec...
- CVSS:
- 6.4
- Affected:
- up to 2.88.14
- Fixed in:
- 2.88.15
- Disclosed:
- Jan 17, 2024
CVE-2024-0420 on NVD →
MapPress Maps for WordPress <= 2.88.15 - Insufficient Authorization to Information Disclosure
medium
The MapPress Maps for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the mapp_get_post AJAX action in all versions up to, and including, 2.88.15. This makes it possible for unauthenticated attackers to read arbitrary private and draft posts.
- CVSS:
- 5.3
- Affected:
- up to 2.88.15
- Fixed in:
- 2.88.16
- Disclosed:
- Jan 17, 2024
CVE-2024-0421 on NVD →
MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.88.14
unknown
[en] The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the map title parameter in all versions up to and including 2.88.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher...
- Affected:
- up to 2.88.14
- Fixed in:
- 2.88.14
- Disclosed:
- Jan 3, 2024
CVE-2023-6524 on NVD →
MapPress Maps for WordPress <= 2.88.13 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the map title parameter in all versions up to and including 2.88.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to in...
- CVSS:
- 6.4
- Affected:
- up to 2.88.13
- Fixed in:
- 2.88.14
- Disclosed:
- Jan 2, 2024
CVE-2023-6524 on NVD →
MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.85.5
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Chris Richardson MapPress Maps for WordPress mappress-google-maps-for-wordpress allows SQL Injection.This issue affects MapPress Maps for WordPress: from n/a through 2.85.4.
- Affected:
- up to 2.85.5
- Fixed in:
- 2.85.5
- Disclosed:
- Nov 3, 2023
CVE-2023-26015 on NVD →
MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.88.5
unknown
[en] The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mappress' shortcode in versions up to, and including, 2.88.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contrib...
- Affected:
- up to 2.88.5
- Fixed in:
- 2.88.5
- Disclosed:
- Sep 12, 2023
CVE-2023-4840 on NVD →
MapPress Maps for WordPress <= 2.88.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mappress' shortcode in versions up to, and including, 2.88.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-...
- CVSS:
- 6.4
- Affected:
- up to 2.88.4
- Fixed in:
- 2.88.5
- Disclosed:
- Sep 11, 2023
CVE-2023-4840 on NVD →
MapPress Maps for WordPress <= 2.85.4 - Authenticated (Contributor+) SQL Injection via get_maps
high
The MapPress Maps for WordPress plugin for WordPress is vulnerable to SQL Injection via the get_maps function in versions up to, and including, 2.85.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attac...
- CVSS:
- 8.8
- Affected:
- up to 2.85.4
- Fixed in:
- 2.85.5
- Disclosed:
- Apr 6, 2023
CVE-2023-26015 on NVD →
MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.73.13
unknown
[en] The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings and upload arbitrary files to the site through the "ajax_save" function. The file is written relative to the current 's stylesheet directory, and a .php file extensio...
- Affected:
- up to 2.73.13
- Fixed in:
- 2.73.13
- Disclosed:
- Apr 4, 2022
CVE-2022-0537 on NVD →
MapPress Maps for WordPress <= 2.73.12 - Admin+ File Upload to Remote Code Execution
medium
The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings and upload arbitrary files to the site through the "ajax_save" function. The file is written relative to the current 's stylesheet directory, and a .php file extension is...
- CVSS:
- 6
- Affected:
- up to 2.73.13
- Fixed in:
- 2.73.13
- Disclosed:
- Mar 14, 2022
CVE-2022-0537 on NVD →
MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.73.4
unknown
[en] The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting it back in the "Bad mapid" error message, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 2.73.4
- Fixed in:
- 2.73.4
- Disclosed:
- Feb 14, 2022
CVE-2022-0208 on NVD →
MapPress Maps <= 2.73.3 - Reflected Cross-Site Scripting
medium
The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting it back in the "Bad mapid" error message, leading to a Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 2.73.4
- Fixed in:
- 2.73.4
- Disclosed:
- Jan 17, 2022
CVE-2022-0208 on NVD →
MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.54.6
unknown
[en] The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related to creation/retrieval/deletion of PHP template files, leading to Remote Code Execution. NOTE: this issue exists because of an incomplete fix for CVE-2020-12077.
- Affected:
- up to 2.54.6
- Fixed in:
- 2.54.6
- Disclosed:
- May 29, 2020
CVE-2020-12675 on NVD →
MapPress Maps <= 2.54.5 - Remote Code Execution via Improper Capability Checks in AJAX Calls
high
The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related to creation/retrieval/deletion of PHP template files, leading to Remote Code Execution. NOTE: this issue exists because of an incomplete fix for CVE-2020-12077.
- CVSS:
- 8.8
- Affected:
- up to 2.54.5
- Fixed in:
- 2.54.6
- Disclosed:
- May 28, 2020
CVE-2020-12675 on NVD →
MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.53.9
unknown
[en] The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions with nonces (or capability checks), leading to remote code execution.
- Affected:
- up to 2.53.9
- Fixed in:
- 2.53.9
- Disclosed:
- Apr 23, 2020
CVE-2020-12077 on NVD →
MapPress Maps for WordPress <=2.53.8 - Authenticated Map Creation/Deletion to Stored Cross-Site Scripting & Remote Code Execution
medium
The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions with nonces (or capability checks), leading to remote code execution.
- CVSS:
- 6.5
- Affected:
- up to 2.53.9
- Fixed in:
- 2.53.9
- Disclosed:
- Apr 1, 2020
CVE-2020-12077 on NVD →
MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.94.9
unknown
- Affected:
- up to 2.94.9
- Fixed in:
- 2.94.9
CVE-2025-2055 on NVD →
MapPress Maps for WordPress [mappress-google-maps-for-wordpress] <= 2.94.10
unknown
- Affected:
- up to 2.94.10
- Fixed in:
- 2.94.10
CVE-2025-2162 on NVD →
MapPress Maps for WordPress [mappress-google-maps-for-wordpress] < 2.93
unknown
- Affected:
- up to 2.93
- Fixed in:
- 2.93
CVE-2024-8620 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database