What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Chris Richardson MapPress Maps for WordPress mappress-google-maps-for-wordpress allows SQL Injection.This issue affects MapPress Maps for WordPress: from n/a through 2.85.4.
Explanation of Vulnerability in Simple Terms
02Summary
MapPress Maps for WordPress versions up to 2.85.4 contain a SQL injection vulnerability in database queries. An authenticated user with low privileges can craft malicious input to extract sensitive data from the WordPress database or degrade site performance. The vulnerability requires a valid user account but no additional user interaction.
What an attacker can do
03Attacker Capabilities
Read sensitive data from the WordPress database or cause the site to slow down or become unavailable.
Potential impact on your site
04Site Impact
Unauthorized access to database contents including user credentials, posts, and configuration; potential site downtime.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
November 3, 2023
CVE published
April 28, 2026
Record updated