CVE-2020-12077: Mappresspro Mappress
High severity, CVSS 8.8. EPSS: 5.5% chance of exploitation in the next 30 days.
The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions with nonces (or capability checks), leading to remote code execution.
Affected products
- Mappresspro Mappress: before 2.53.9 (fixed in 2.53.9)
Published 2020-04-23. Last modified 2026-06-17.