Junglewise Threat Intelligence

CVE-2026-65564: MapPress Maps for WordPress sensitive data exposure

CVE-2026-65564 · Severity: medium · CVSS 5.3 · Published 2026-07-27

Technologies: Chrisvrichardson MapPress Maps for WordPress. Vendors: MapPress.

Executive brief

MapPress Maps is a WordPress plugin used to create and manage interactive maps on websites. A security flaw in versions 2.97.6 and earlier allows unauthorized individuals to access sensitive system information that should be restricted. This exposure could provide attackers with technical details needed to plan more sophisticated attacks against the website.

Technical details

The MapPress Maps for WordPress plugin (versions <= 2.97.6) suffers from an unauthenticated sensitive data exposure vulnerability (CWE-497). The flaw allows a remote attacker to access sensitive system information without any prior authentication or user interaction. This is likely due to improper access controls on specific plugin components or debug outputs. Attackers can leverage this information to gain insights into the server environment or application structure, potentially facilitating further exploitation. The issue is resolved in version 2.97.7.

Affected products

  • chrisvrichardson MapPress Maps for WordPress <= 2.97.6

Timeline

  • 2026-07-16: disclosed: Reported by Ananda Dhakal via Patchstack
  • 2026-07-24: advisory: Patchstack published advisory
  • 2026-07-27: patched: Fix available in version 2.97.7

References

Related threats