Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mappress MEDIUM 6.8
CVE-2025-2055

The MapPress Maps for WordPress plugin before 2.94.9 does not sanitise and escape some parameters when outputing them in the page, which could allow …

Fix: 2.94.9+
Fix from $1,600 2025-04-03
Mappress MEDIUM 5.4
CVE-2024-10715

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map block in all versions up to, a…

Fix: 2.94.2+
Fix from $1,600 2024-11-06
Mappress Maps For Wordpress MEDIUM 5.4
CVE-2024-0420

The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back in the admin dashboard, allo…

Fix: 2.88.15+
Fix from $1,600 2024-02-12
Mappress Maps For Wordpress MEDIUM 5.3
CVE-2024-0421

The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retrieve via an AJAX action is a …

Fix: 2.88.16+
Fix from $1,600 2024-02-12
Mappress MEDIUM 5.4
CVE-2023-7225

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the width and height parameters in all versions…

Fix: after 2.88.16
Fix from $1,600 2024-01-30
Mappress MEDIUM 5.4
CVE-2023-6524

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the map title parameter in all versions up to a…

Fix: 2.88.14+
Fix from $1,600 2024-01-03
Mappress CRITICAL 9.8
CVE-2023-26015

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Chris Richardson MapPress Maps for WordPress ma…

Fix: after 2.85.4
Fix from $2,300 2023-11-03
Mappress MEDIUM 5.4
CVE-2023-4840

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mappress' shortcode in versions up to, and inc…

Fix: after 2.88.4
Fix from $1,600 2023-09-12
Mappress HIGH 7.2
CVE-2022-0537

The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings …

Fix: 2.73.13+
Fix from $1,950 2022-04-04
Mappress MEDIUM 6.1
CVE-2022-0208

The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting it back in the "Bad mapid" er…

Fix: 2.73.4+
Fix from $1,600 2022-02-14
Mappress HIGH 8.8
CVE-2020-12675

The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related t…

Fix: 2.54.6+
Fix from $1,950 2020-05-29
Mappress HIGH 8.8
CVE-2020-12077EPSS 6%

The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions with nonces (or capability chec…

Fix: 2.53.9+
Fix from $1,950 2020-04-23