Mappresspro
Mappresspro Mappress: vulnerabilidades y CVE
Mappresspro Mappress tiene 13 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses1
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-65564 | Media (5.3) | 0.33% | — | 27 jul 2026 | Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions. |
| CVE-2024-8620 | Media (4.8) | 0.31% | — | 15 may 2025 | The MapPress Maps for WordPress plugin before 2.93 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2025-2162 | Media (4.8) | 0.39% | — | 18 abr 2025 | The MapPress Maps for WordPress plugin before 2.94.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2025-2055 | Media (6.8) | 0.46% | — | 3 abr 2025 | The MapPress Maps for WordPress plugin before 2.94.9 does not sanitise and escape some parameters when outputing them in the page, which could allow users with a role as low as contributor to perform Cross-Site… |
| CVE-2024-10715 | Media (5.4) | 0.26% | — | 6 nov 2024 | The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map block in all versions up to, and including, 2.94.1 due to insufficient input sanitization and output… |
| CVE-2023-7225 | Media (5.4) | 0.49% | — | 30 ene 2024 | The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the width and height parameters in all versions up to, and including, 2.88.16 due to insufficient input sanitization… |
| CVE-2023-6524 | Media (5.4) | 0.54% | — | 3 ene 2024 | The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the map title parameter in all versions up to and including 2.88.13 due to insufficient input sanitization and output… |
| CVE-2023-26015 | Crítica (9.8) | 0.73% | — | 3 nov 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Chris Richardson MapPress Maps for WordPress mappress-google-maps-for-wordpress allows SQL Injection.This issue… |
| CVE-2023-4840 | Media (5.4) | 0.55% | — | 12 sept 2023 | The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mappress' shortcode in versions up to, and including, 2.88.4 due to insufficient input sanitization and output… |
| CVE-2022-0537 | Alta (7.2) | 1.5% | — | 4 abr 2022 | The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings and upload arbitrary files to the site through the "ajax_save"… |
| CVE-2022-0208 | Media (6.1) | 2.0% | — | 14 feb 2022 | The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting it back in the "Bad mapid" error message, leading to a Reflected Cross-Site Scripting |
| CVE-2020-12675 | Alta (8.8) | 2.8% | — | 29 may 2020 | The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related to creation/retrieval/deletion of PHP template files, leading to Remote… |
| CVE-2020-12077 | Alta (8.8) | 5.5% | — | 23 abr 2020 | The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions with nonces (or capability checks), leading to remote code execution. |