Extension WordPress
Vulnérabilités MapPress Maps for WordPress
Cette page rassemble les failles publiées pour MapPress Maps for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de MapPress Maps for WordPress
16 fiches
MapPress Maps for WordPress <= 2.97.3 – Unauthenticated Stored Cross-Site Scripting
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.97.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-2.97.3
2.97.4
19/06/2026
MapPress Maps for WordPress <= 2.96.6 – Unauthenticated Insecure Direct Object Reference via REST API Endpoints
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.96.6. This is due to missing ownership verification in the REST API routes registered via…
*-2.96.6
2.97.1
05/06/2026
MapPress Maps for WordPress <= 2.94.9 – Authenticated (Administrator+) Stored Cross-Site Scripting
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.94.9 due to insufficient input sanitization and output escaping. This makes it possible for…
*-2.94.9
2.94.10
27/03/2025
MapPress Maps for WordPress <= 2.94.8 – Authenticated (Contributor+) Stored Cross-Site Scripting
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.94.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-2.94.8
2.94.9
13/03/2025
MapPress Maps for WordPress <= 2.94.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Map Block
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map block in all versions up to, and including, 2.94.1 due to insufficient input sanitization and output escaping on user supplied…
*-2.94.1
2.94.2
05/11/2024
MapPress Maps for WordPress <= 2.92.2 – Authenticated (Administrator+) Stored Cross-Site Scripting
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.92.2 due to insufficient input sanitization and output escaping. This makes it possible for…
*-2.92.2
2.93
24/09/2024
MapPress <= 2.88.16 – Authenticated (Contributor+) Stored Cross-Site Scripting via Map Settings
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the width and height parameters in all versions up to, and including, 2.88.16 due to insufficient input sanitization and output escaping. This makes…
*-2.88.16
2.88.17
29/01/2024
MapPress Maps for WordPress <= 2.88.15 – Insufficient Authorization to Information Disclosure
The MapPress Maps for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the mapp_get_post AJAX action in all versions up to, and including, 2.88.15. This makes it possible…
*-2.88.15
2.88.16
17/01/2024
MapPress Maps for WordPress <= 2.88.14 – Authenticated (Contributor+) Stored Cross-Site Scripting
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via map titles in all versions up to, and including, 2.88.14 due to insufficient input sanitization and output escaping. This makes it possible for…
*-2.88.14
2.88.15
17/01/2024
MapPress Maps for WordPress <= 2.88.13 – Authenticated (Contributor+) Stored Cross-Site Scripting
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the map title parameter in all versions up to and including 2.88.13 due to insufficient input sanitization and output escaping. This makes it…
*-2.88.13
2.88.14
02/01/2024
MapPress Maps for WordPress <= 2.88.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mappress' shortcode in versions up to, and including, 2.88.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-2.88.4
2.88.5
11/09/2023
MapPress Maps for WordPress <= 2.85.4 – Authenticated (Contributor+) SQL Injection via get_maps
The MapPress Maps for WordPress plugin for WordPress is vulnerable to SQL Injection via the get_maps function in versions up to, and including, 2.85.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-2.85.4
2.85.5
06/04/2023
MapPress Maps for WordPress <= 2.73.12 – Admin+ File Upload to Remote Code Execution
The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings and upload arbitrary files to the site through the "ajax_save" function. The file is written relative to the…
[*, 2.73.13)
2.73.13
14/03/2022
MapPress Maps <= 2.73.3 – Reflected Cross-Site Scripting
The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting it back in the "Bad mapid" error message, leading to a Reflected Cross-Site Scripting
[*, 2.73.4)
2.73.4
17/01/2022
MapPress Maps <= 2.54.5 – Remote Code Execution via Improper Capability Checks in AJAX Calls
The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related to creation/retrieval/deletion of PHP template files, leading to Remote Code Execution. NOTE: this issue exists because of an incomplete fix for…
*-2.54.5
2.54.6
28/05/2020
MapPress Maps for WordPress <=2.53.8 – Authenticated Map Creation/Deletion to Stored Cross-Site Scripting & Remote Code Execution
The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions with nonces (or capability checks), leading to remote code execution.
[*, 2.53.9)
2.53.9
01/04/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.