PT-2026-67051 · WordPress · Mapster Wp Maps
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mapster WP Maps versions prior to 1.24.0
Description
A public REST endpoint fails to perform authorization or post-status checks. This allows unauthenticated users to retrieve the title and full content of any post, including those that are unpublished, such as drafts, pending, private, or trashed posts.
Recommendations
Update Mapster WP Maps to version 1.24.0 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mapster Wp Maps