Extension WordPress

Vulnérabilités MapPress Maps for WordPress

Cette page rassemble les failles publiées pour MapPress Maps for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.

16Vulnérabilités
0Critiques
16Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de MapPress Maps for WordPress

16 fiches

CVE-2026-56011 Élevée · 7,2
MapPress Maps for WordPress

MapPress Maps for WordPress <= 2.97.3 – Unauthenticated Stored Cross-Site Scripting

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.97.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

Versions affectées

*-2.97.3

Correctif

2.97.4

Publication

19/06/2026

CVE-2026-8839 Moyenne · 5,3
MapPress Maps for WordPress

MapPress Maps for WordPress <= 2.96.6 – Unauthenticated Insecure Direct Object Reference via REST API Endpoints

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.96.6. This is due to missing ownership verification in the REST API routes registered via…

Versions affectées

*-2.96.6

Correctif

2.97.1

Publication

05/06/2026

CVE-2025-2162 Moyenne · 4,4
MapPress Maps for WordPress

MapPress Maps for WordPress <= 2.94.9 – Authenticated (Administrator+) Stored Cross-Site Scripting

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.94.9 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-2.94.9

Correctif

2.94.10

Publication

27/03/2025

CVE-2025-2055 Moyenne · 6,4
MapPress Maps for WordPress

MapPress Maps for WordPress <= 2.94.8 – Authenticated (Contributor+) Stored Cross-Site Scripting

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.94.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-2.94.8

Correctif

2.94.9

Publication

13/03/2025

CVE-2024-10715 Moyenne · 6,4
MapPress Maps for WordPress

MapPress Maps for WordPress <= 2.94.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Map Block

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map block in all versions up to, and including, 2.94.1 due to insufficient input sanitization and output escaping on user supplied…

Versions affectées

*-2.94.1

Correctif

2.94.2

Publication

05/11/2024

CVE-2024-8620 Moyenne · 4,4
MapPress Maps for WordPress

MapPress Maps for WordPress <= 2.92.2 – Authenticated (Administrator+) Stored Cross-Site Scripting

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.92.2 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-2.92.2

Correctif

2.93

Publication

24/09/2024

CVE-2023-7225 Moyenne · 6,4
MapPress Maps for WordPress

MapPress <= 2.88.16 – Authenticated (Contributor+) Stored Cross-Site Scripting via Map Settings

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the width and height parameters in all versions up to, and including, 2.88.16 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-2.88.16

Correctif

2.88.17

Publication

29/01/2024

CVE-2024-0420 Moyenne · 6,4
MapPress Maps for WordPress

MapPress Maps for WordPress <= 2.88.14 – Authenticated (Contributor+) Stored Cross-Site Scripting

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via map titles in all versions up to, and including, 2.88.14 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-2.88.14

Correctif

2.88.15

Publication

17/01/2024

CVE-2023-6524 Moyenne · 6,4
MapPress Maps for WordPress

MapPress Maps for WordPress <= 2.88.13 – Authenticated (Contributor+) Stored Cross-Site Scripting

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the map title parameter in all versions up to and including 2.88.13 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-2.88.13

Correctif

2.88.14

Publication

02/01/2024

CVE-2023-4840 Moyenne · 6,4
MapPress Maps for WordPress

MapPress Maps for WordPress <= 2.88.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mappress' shortcode in versions up to, and including, 2.88.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

Versions affectées

*-2.88.4

Correctif

2.88.5

Publication

11/09/2023

CVE-2023-26015 Élevée · 8,8
MapPress Maps for WordPress

MapPress Maps for WordPress <= 2.85.4 – Authenticated (Contributor+) SQL Injection via get_maps

The MapPress Maps for WordPress plugin for WordPress is vulnerable to SQL Injection via the get_maps function in versions up to, and including, 2.85.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

Versions affectées

*-2.85.4

Correctif

2.85.5

Publication

06/04/2023

CVE-2022-0537 Moyenne · 6,0
MapPress Maps for WordPress

MapPress Maps for WordPress <= 2.73.12 – Admin+ File Upload to Remote Code Execution

The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings and upload arbitrary files to the site through the "ajax_save" function. The file is written relative to the…

Versions affectées

[*, 2.73.13)

Correctif

2.73.13

Publication

14/03/2022

CVE-2020-12675 Élevée · 8,8
MapPress Maps for WordPress

MapPress Maps <= 2.54.5 – Remote Code Execution via Improper Capability Checks in AJAX Calls

The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related to creation/retrieval/deletion of PHP template files, leading to Remote Code Execution. NOTE: this issue exists because of an incomplete fix for…

Versions affectées

*-2.54.5

Correctif

2.54.6

Publication

28/05/2020

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités