Medium severity5.3NVD Advisory· Published Feb 12, 2024· Updated Jun 17, 2026
CVE-2024-0421
CVE-2024-0421
Description
The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retrieve via an AJAX action is a public map, allowing unauthenticated users to read arbitrary private and draft posts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:mappresspro:mappress_maps_for_wordpress:*:*:*:*:*:wordpress:*:*Range: <2.88.16
- WordPress/MapPress Mapsdescription
- Range: <2.88.16
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/587acc47-1966-4baf-a380-6aa479a97c82/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.