
CVE-2025-2055 – MapPress Maps for WordPress < 2.94.9 - Contributor+ Stored XSS
https://notcve.org/view.php?id=CVE-2025-2055
03 Apr 2025 — The MapPress Maps for WordPress plugin before 2.94.9 does not sanitise and escape some parameters when outputing them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks. • https://wpscan.com/vulnerability/a8bfdbbf-6963-4fab-826a-6be770ac72c3 •

CVE-2024-10715 – MapPress Maps for WordPress <= 2.94.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Block
https://notcve.org/view.php?id=CVE-2024-10715
05 Nov 2024 — The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map block in all versions up to, and including, 2.94.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. • https://plugins.trac.wordpress.org/changeset/3180900/mappress-google-maps-for-wordpress • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-7225 – MapPress <= 2.88.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Settings
https://notcve.org/view.php?id=CVE-2023-7225
29 Jan 2024 — The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the width and height parameters in all versions up to, and including, 2.88.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. El complemento MapPress Maps for WordPress para WordPress es vulnerable a Cross-Sit... • https://advisory.abay.sh/cve-2023-7225 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-0420 – MapPress Maps for WordPress < 2.88.15 - Contributor+ Stored XSS
https://notcve.org/view.php?id=CVE-2024-0420
17 Jan 2024 — The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back in the admin dashboard, allowing Contributors and above roles to perform Stored Cross-Site Scripting attacks El complemento MapPress Maps para WordPress anterior a 2.88.15 no sanitiza ni escapa el título del mapa cuando lo muestra nuevamente en el panel de administración, lo que permite a los colaboradores y roles superiores realizar ataques de Cross-Site Scripting Almacenado. The MapPres... • https://wpscan.com/vulnerability/b6187ef8-70f4-4911-abd7-42bf6b7e54b7 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-0421 – MapPress Maps for WordPress < 2.88.16 - Unauthenticated Arbitrary Private/Draft Post Disclosure
https://notcve.org/view.php?id=CVE-2024-0421
17 Jan 2024 — The MapPress Maps for WordPress plugin before 2.88.16 does not ensure that posts to be retrieve via an AJAX action is a public map, allowing unauthenticated users to read arbitrary private and draft posts. El complemento MapPress Maps para WordPress anterior a 2.88.16 no garantiza que las publicaciones que se recuperarán mediante una acción AJAX sean un mapa público, lo que permite a usuarios no autenticados leer publicaciones arbitrarias privadas y borradores. The MapPress Maps for WordPress plugin before ... • https://wpscan.com/vulnerability/587acc47-1966-4baf-a380-6aa479a97c82 • CWE-862: Missing Authorization •

CVE-2023-4840 – MapPress Maps for WordPress <= 2.88.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
https://notcve.org/view.php?id=CVE-2023-4840
11 Sep 2023 — The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mappress' shortcode in versions up to, and including, 2.88.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. El complemento MapPress Maps de WordPress para WordPress es vu... • https://plugins.trac.wordpress.org/browser/mappress-google-maps-for-wordpress/tags/2.88.4/mappress_map.php#L381 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-26015 – WordPress MapPress Maps for WordPress Plugin <= 2.85.4 is vulnerable to SQL Injection
https://notcve.org/view.php?id=CVE-2023-26015
06 Apr 2023 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Chris Richardson MapPress Maps for WordPress mappress-google-maps-for-wordpress allows SQL Injection.This issue affects MapPress Maps for WordPress: from n/a through 2.85.4. Neutralización inadecuada de elementos especiales utilizados en una vulnerabilidad de comando SQL ('Inyección SQL') en Chris Richardson MapPress Maps para WordPress mappress-google-maps-for-wordpress permite la inyección SQL. Este probl... • https://patchstack.com/database/vulnerability/mappress-google-maps-for-wordpress/wordpress-mappress-maps-for-wordpress-plugin-2-85-4-authenticated-sql-injection-vulnerability?_s_id=cve • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •