CVE-2024-0421

CVE-2024-0421: MapPress Maps for WordPress < 2.88.16 - Unauthenticated Arbitrary Private/Draft Post Disclosure

Vendor Unknown
Product MapPress Maps for WordPress
Published February 12, 2024
Last update May 7, 2025

CVSS base score

What the vulnerability does

01Description

The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retrieve via an AJAX action is a public map, allowing unauthenticated users to read arbitrary private and draft posts.

Key dates

02Disclosure timeline

February 12, 2024 CVE published
May 7, 2025 Record updated