PT-2026-95282 · WordPress · Mapster Wp Maps

·

CVE-2026-12954

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mapster WP Maps versions prior to 1.23.1
Description The plugin contains an Arbitrary User Meta Write flaw within the my profile update() function. The issue occurs because the function fails to perform nonce verification, capability checks, and allowlist validation on the meta key provided through the acf-photo-gallery-groups POST parameter before passing the key and value to update user meta(). Authenticated users with Subscriber-level access or higher can exploit this to update arbitrary user meta values, although this cannot be used for privilege escalation.
Recommendations Update Mapster WP Maps to a version newer than 1.23.0. As a temporary mitigation, restrict access to the my profile update() function or avoid using the acf-photo-gallery-groups parameter.

Fix

LPE

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12954

Affected Products

Mapster Wp Maps