CVE-2024-0421: Mappresspro Mappress Maps For WordPress

Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.

The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retrieve via an AJAX action is a public map, allowing unauthenticated users to read arbitrary private and draft posts.

Affected products

  • Mappresspro Mappress Maps For WordPress: before 2.88.16 (fixed in 2.88.16)

Published 2024-02-12. Last modified 2026-06-17.