← WordPress Vulnerabilities
WordPress security by component

MapPress Maps for WordPress

MapPress Maps for WordPress is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: mappress-google-maps-for-wordpress

CVE-2026-65564: MapPress exposes protected data without authentication

MapPress through 2.97.6 permits an unauthenticated request to retrieve protected data. The Patchstack CNA record does not disclose the endpoint, action, parameter, function or data fields returned, so the sensitivity and practical scope of the disclosure remain unknown.

PublishedJul 27, 2026
Known safe version2.97.7
Safe version
Jul 27, 2026 CVE-2026-65564
MapPress exposes protected data without authentication
MapPress through 2.97.6 permits an unauthenticated request to retrieve protected data. The Patchstack CNA record does not disclose the endpoint, action, parameter, function or data fields returned, so the sensitivity and practical scope of the disclosure remain unknown.
2.97.7
CVE5.3
NVDPending
Jun 26, 2026 CVE-2026-56011
MapPress Maps for WordPress: Cross-site scripting
MapPress Maps for WordPress is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.97.3.
2.97.4
CVE7.1
NVDPending
Jun 06, 2026 CVE-2026-8839
MapPress Maps for WordPress: A security weakness
MapPress Maps for WordPress is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.96.6.
> 2.96.6
CVE5.3
NVDPending
Nov 03, 2023 CVE-2023-26015
MapPress Maps for WordPress: SQL injection
MapPress Maps for WordPress is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.1
NVD9.8
Sep 12, 2023 CVE-2023-4840
MapPress Maps for: Cross-site scripting
MapPress Maps for is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 29, 2020 CVE-2020-12675
Mappress Google Maps For Wordpress: Code execution
Mappress Google Maps For Wordpress is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVD8.8
Apr 23, 2020 CVE-2020-12077
Mappress Google Maps For Wordpress: Code execution
Mappress Google Maps For Wordpress is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVD8.8