Executive brief
MapPress Maps is a WordPress plugin used to embed interactive Google and Leaflet maps into websites. A security vulnerability allows unauthenticated attackers to inject malicious scripts into the site, which could lead to unauthorized redirects, theft of user session data, or the display of fraudulent content to visitors. This occurs when a victim, such as a site administrator, interacts with a specially crafted link or page created by the attacker.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the MapPress Maps for WordPress plugin due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript or HTML payloads. Exploitation requires a victim with an active session to interact with a malicious link or visit a crafted page (User Interaction required). Successful exploitation can lead to session hijacking, unauthorized administrative actions, or website defacement. The issue is addressed in version 2.97.4.
Affected products
- chrisvrichardson MapPress Maps for WordPress <= 2.97.3
Timeline
- 2026-06-08: other: Vulnerability reported by researcher l3m3s
- 2026-06-19: advisory: Patchstack advisory published
- 2026-06-26: disclosed: CVE published to NVD dataset
- 2026-06-26: patched: Patch confirmed available in version 2.97.4