Description
The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` function. This is due to the function performing no nonce verification, no capability check, and no allowlist validation on the meta key supplied via the `acf-photo-gallery-groups` POST parameter before passing both the meta key and its corresponding value directly to `update_user_meta()`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary user meta values, though privilege escalation is not possible.
Published: 2026-09-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary User Meta Write
Action: Apply Patch
AI Analysis

Impact

The Mapster WP Maps plugin contains a flaw that lets an authenticated user alter any user’s meta data without performing nonce verification, capability checks, or input validation on the meta key supplied through the acf-photo-gallery-groups POST parameter. This flaw means that an attacker who can log into the site with Subscriber-level access or higher can freely write arbitrary key/value pairs into the user_meta table for any user account, potentially altering sensitive application data or setting values that future code may trust. The vulnerability is a classic input validation issue (CWE‑20) and results in a data integrity breach, but it does not provide privilege escalation to higher roles.

Affected Systems

The flaw affects all releases of the Mapster WP Maps plugin with version numbers up to and including 1.23.0. The affected product is the Mapster WP Maps plugin for WordPress, distributed by the vendor Mapster.

Risk and Exploitability

The CVSS score of 8.8 categorizes the issue as high severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, which reduces its prominence among known exploited weaknesses. The attack vector is likely network-based, requiring the attacker to be authenticated to the WordPress installation, so any user with a Subscriber role or higher can trigger the flaw by submitting a crafted POST request containing an acf-photo-gallery-groups parameter with an arbitrary meta key and value.

Generated by OpenCVE AI on September 19, 2026 at 20:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Mapster WP Maps plugin to a version newer than 1.23.0 that includes the fix for the arbitrary user meta write vulnerability.
  • If an update cannot be performed immediately, restrict the ability to write user meta by disabling the my_profile_update() function or blocking the acf-photo-gallery-groups POST parameter with an input filter or firewall rule that permits only approved meta keys.
  • After applying the patch or implementing the workaround, verify that no unauthorized meta keys can be written by submitting a test value for acf-photo-gallery-groups and ensuring the update_user_meta() call no longer executes.

Generated by OpenCVE AI on September 19, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Mapster
Mapster mapster Wp Maps
Wordpress
Wordpress wordpress
Vendors & Products Mapster
Mapster mapster Wp Maps
Wordpress
Wordpress wordpress

Fri, 18 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` function. This is due to the function performing no nonce verification, no capability check, and no allowlist validation on the meta key supplied via the `acf-photo-gallery-groups` POST parameter before passing both the meta key and its corresponding value directly to `update_user_meta()`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary user meta values, though privilege escalation is not possible.
Title Mapster WP Maps <= 1.23.0 - Authenticated (Subscriber+) Arbitrary User Meta Write via 'acf-photo-gallery-groups' Parameter
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Mapster Mapster Wp Maps
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:21:51.866Z

Reserved: 2026-06-22T21:18:38.522Z

Link: CVE-2026-12954

cve-icon Vulnrichment

Updated: 2026-09-19T14:13:54.459Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T08:16:59.100

Modified: 2026-09-19T15:16:58.133

Link: CVE-2026-12954

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:30:07Z

Weaknesses
  • CWE-20

    Improper Input Validation