Executive brief
Mapster WP Maps, a WordPress plugin used for creating interactive maps, contains a security flaw that allows unauthorized individuals to view restricted content. An attacker can access the full text and titles of posts that are not yet published, including drafts, private posts, and items in the trash. This could lead to the premature disclosure of sensitive information or internal business plans stored within the website's database.
Technical details
The Mapster WP Maps plugin for WordPress fails to implement proper authorization checks or post-status validation on one of its public REST API endpoints. This vulnerability is classified as an Information Exposure (CWE-200). An unauthenticated remote attacker can query this endpoint to retrieve the titles and full content of any post on the WordPress site, bypassing standard visibility restrictions. This includes posts marked as draft, pending, private, or trashed. The issue is resolved in version 1.24.0.
Affected products
- Mapster Mapster WP Maps < 1.24.0
Timeline
- 2026-07-20: disclosed: Publicly published by WPScan
- 2026-07-20: patched: Fixed in version 1.24.0
- 2026-08-01: advisory: NVD publication date