Description
Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.
Published: 2026-07-27
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated sensitive data exposure in the MapPress Maps for WordPress plugin version 2.97.6 and earlier. Attackers can retrieve unintended data from the plugin without any authentication, potentially exposing private information stored or displayed by the plugin. The weakness, identified as CWE‑497, indicates a failure to properly enforce access controls over data storage or network interfaces.

Affected Systems

The affected vendor is chrisvrichardson and the product is the MapPress Maps for WordPress plugin. All installations using version 2.97.6 or earlier are impacted; version 2.97.7 and later contain the fix.

Risk and Exploitability

With a CVSS score of 5.3, the severity is considered medium. The EPSS score of 0.00197 indicates a very low exploitation probability, less than 1%, while the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated HTTP request to a plugin endpoint, inferred from the description. No authentication or elevated privileges are required, making the vulnerability straightforward to exploit if an attacker can reach the affected site.

Generated by OpenCVE AI on August 3, 2026 at 17:28 UTC.

Remediation

Vendor Solution

Update the WordPress MapPress Maps for WordPress Plugin to the latest available version (at least 2.97.7).


OpenCVE Recommended Actions

  • Update the MapPress Maps for WordPress plugin to version 2.97.7 or later.
  • Restrict unauthenticated access to the plugin’s data endpoints, for example by configuring role‑based permissions or adjusting settings in a security plugin to block direct requests.
  • Monitor the site’s access logs for unexpected requests to the plugin and take corrective action if suspicious activity is detected.

Generated by OpenCVE AI on August 3, 2026 at 17:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Chrisrichardson
Chrisrichardson mappress Maps For Wordpress
Wordpress
Wordpress wordpress
Vendors & Products Chrisrichardson
Chrisrichardson mappress Maps For Wordpress
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.
Title WordPress MapPress Maps for WordPress plugin <= 2.97.6 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Chrisrichardson Mappress Maps For Wordpress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T18:15:15.556Z

Reserved: 2026-07-22T08:54:32.759Z

Link: CVE-2026-65564

cve-icon Vulnrichment

Updated: 2026-07-27T18:15:10.523Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:09.807

Modified: 2026-07-27T19:17:22.047

Link: CVE-2026-65564

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:30:17Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere