VYPR

MapPress Maps for WordPress

by WordPress

CVEs (3)

  • CVE-2023-26015HigNov 3, 2023
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Chris Richardson MapPress Maps for WordPress mappress-google-maps-for-wordpress allows SQL Injection.This issue affects MapPress Maps for WordPress: from n/a through 2.85.4.

  • CVE-2026-8839MedJun 6, 2026
    risk 0.34cvss 5.3epss

    The MapPress Maps for WordPress plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.96.6. This is due to missing ownership verification in the REST API routes registered via…

  • CVE-2024-0421Feb 12, 2024
    risk 0.00cvss epss 0.00

    The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retrieve via an AJAX action is a public map, allowing unauthenticated users to read arbitrary private and draft posts.