Skip to content
Noroxi

MapPress – Google Maps, OpenStreetMap & Leaflet

mappress-google-maps-for-wordpress · plugin

Known security vulnerabilities for MapPress – Google Maps, OpenStreetMap & Leaflet. Find out in seconds which version runs on your site with WP Lens.

10 known vulnerabilities

1 critical · 3 exploitable without logging in · 3 with public exploit code · latest Jul 27, 2026

Listed on wordpress.org · latest 2.97.14 · last updated Sep 28, 2026 · 30K+ installs

wordpress.org status checked on Oct 2, 2026

Vulnerabilities

  • CVE-2023-26015login required≤ 2.85.4

    WordPress MapPress Maps for WordPress Plugin <= 2.85.4 is vulnerable to SQL Injection

    Critical 9.8
  • CVE-2020-12675login required

    The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions

    High 8.8
  • CVE-2020-12077login required

    The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions with nonces (or capabi

    High 8.8
  • CVE-2026-56011unauthenticated · needs a click≤ 2.97.3

    WordPress MapPress Maps for WordPress plugin <= 2.97.3 - Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2024-10715contributor+≤ 2.94.1

    MapPress Maps for WordPress <= 2.94.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Block

    Medium 5.4
  • CVE-2023-7225contributor+≤ 2.88.16

    MapPress <= 2.88.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Settings

    Medium 5.4
  • CVE-2023-6524contributor+≤ 2.88.13

    MapPress Maps for WordPress <= 2.88.13 - Authenticated (Contributor+) Stored Cross-Site Scripting

    Medium 5.4
  • CVE-2023-4840contributor+≤ 2.88.4

    MapPress Maps for WordPress <= 2.88.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    Medium 5.4
  • CVE-2026-65564unauthenticated≤ 2.97.6

    WordPress MapPress Maps for WordPress plugin <= 2.97.6 - Sensitive Data Exposure vulnerability

    Medium 5.3
  • CVE-2026-8839unauthenticated≤ 2.96.6

    MapPress Maps for WordPress <= 2.96.6 - Unauthenticated Insecure Direct Object Reference via REST API Endpoints

    Medium 5.3

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory