CVE-2024-0421 Information

Description

The MapPress Maps for WordPress plugin before 2.88.16 does not ensure that posts to be retrieve via an AJAX action is a public map allowing unauthenticated users to read arbitrary private and draft posts.

Reference

https://wpscan.com/vulnerability/587acc47-1966-4baf-a380-6aa479a97c82/

Share on: