Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

MapPress Maps for WordPress — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in MapPress Maps for WordPress, with AI-generated Chinese analysis, references, and POCs.

This page details vulnerability aggregation for the MapPress Maps for WordPress plugin, focusing on security weaknesses within the WordPress ecosystem. It compiles a comprehensive collection of identified flaws and security issues, covering data ranging from initial disclosures through to recent remediation efforts in the current year. Visitors can utilize this resource to track vendor advisories as they are released, gain a deeper understanding of specific weakness classes affecting the plugin, and review the complete vulnerability history associated with this particular product. By consolidating these details, the page serves as a centralized reference point for security professionals, developers, and site administrators who need to assess the current risk posture of installations using MapPress Maps. The information provided is structured to facilitate rapid identification of potential threats and to aid in the prioritization of patching efforts. Understanding the nature of these vulnerabilities is critical for maintaining the integrity and security of WordPress-based websites that rely on this mapping functionality. This aggregation does not replace official vendor advisories but rather complements them by providing context and historical data. Users are encouraged to consult the linked resources for detailed technical analysis and mitigation strategies. The goal is to empower stakeholders with the knowledge necessary to make informed decisions regarding software updates and security configurations. This continuous monitoring of vulnerability data helps in establishing a proactive security posture rather than a reactive one.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2026-8839 MapPress Maps for WordPress <= 2.96.6 - Unauthenticated Insecure Direct Object Reference via REST API Endpoints CWE-639 5.3 Medium2026-06-06
CVE-2024-8620 MapPress Maps for WordPress < 2.93 - Admin+ Stored XSS via Map Settings 4.8AIMediumAI2025-05-15
CVE-2025-2162 MapPress Maps for WordPress < 2.94.10 - Admin+ Stored XSS 4.8 -2025-04-18
CVE-2025-2055 MapPress Maps for WordPress < 2.94.9 - Contributor+ Stored XSS 5.4AIMediumAI2025-04-03
CVE-2024-10715 MapPress Maps for WordPress <= 2.94.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Block CWE-79 6.4 Medium2024-11-06
CVE-2024-0420 MapPress Maps for WordPress < 2.88.15 - Contributor+ Stored XSS 5.4 -2024-02-12
CVE-2024-0421 MapPress Maps for WordPress < 2.88.16 - Unauthenticated Arbitrary Private/Draft Post Disclosure 5.3 -2024-02-12
CVE-2023-7225 MapPress <= 2.88.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Settings CWE-79 6.4 Medium2024-01-30
CVE-2023-6524 MapPress Maps for WordPress <= 2.88.13 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-01-03
CVE-2023-26015 WordPress MapPress Maps for WordPress Plugin <= 2.85.4 is vulnerable to SQL Injection CWE-89 7.1 High2023-11-03
CVE-2023-4840 MapPress Maps for WordPress <= 2.88.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium2023-09-12
CVE-2022-0537 MapPress Maps for WordPress < 2.73.13 - Admin+ File Upload to Remote Code Execution CWE-434 7.2 -2022-04-04
CVE-2022-0208 MapPress Maps for WordPress < 2.73.4 - Reflected Cross-Site scripting CWE-79 6.1 -2022-02-14

All 13 known CVE vulnerabilities affecting MapPress Maps for WordPress with full Chinese analysis, references, and POCs where available.