Impact
The vulnerability is an unauthenticated sensitive data exposure in the MapPress Maps for WordPress plugin version 2.97.6 and earlier. Attackers can retrieve unintended data from the plugin without any authentication, potentially exposing private information stored or displayed by the plugin. The weakness, identified as CWE‑497, indicates a failure to properly enforce access controls over data storage or network interfaces.
Affected Systems
The affected vendor is chrisvrichardson and the product is the MapPress Maps for WordPress plugin. All installations using version 2.97.6 or earlier are impacted; version 2.97.7 and later contain the fix.
Risk and Exploitability
With a CVSS score of 5.3, the severity is considered medium. The EPSS score of 0.00197 indicates a very low exploitation probability, less than 1%, while the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated HTTP request to a plugin endpoint, inferred from the description. No authentication or elevated privileges are required, making the vulnerability straightforward to exploit if an attacker can reach the affected site.
OpenCVE Enrichment