WordPress · Mapster Wp Maps · CVE-2026-14839
**Name of the Vulnerable Software and Affected Versions**
Mapster WP Maps versions prior to 1.24.0
**Description**
A public REST endpoint fails to perform authorization or post-status checks. This allows unauthenticated users to retrieve the title and full content of any post, including those that are unpublished, such as drafts, pending, private, or trashed posts.
**Recommendations**
Update Mapster WP Maps to version 1.24.0 or later.