CVE-2024-0420: medium-severity vulnerability in MapPress Maps for WordPress
MapPress Maps for WordPress < 2.88.15 - Contributor+ Stored XSS
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.1epss 0.5%
exploitation probability
0.5%top 62% of all CVEs
observed exploitation
nono source reports it
The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back in the admin dashboard, allowing Contributors and above roles to perform Stored Cross-Site Scripting attacks
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
Unknown · MapPress Maps for WordPressRelated CVEs — MapPress Maps for WordPress
In the same product, most dangerous first.
CVE-2022-0208—MapPress Maps for WordPress < 2.73.4 - Reflected Cross-Site scriptingEPSS 2.0%CVE-2022-0537—MapPress Maps for WordPress < 2.73.13 - Admin+ File Upload to Remote Code ExecutionEPSS 1.5%CVE-2024-0421MEDIUMMapPress Maps for WordPress < 2.88.16 - Unauthenticated Arbitrary Private/Draft Post DisclosureEPSS 0.6%CVE-2025-2055MEDIUMMapPress Maps for WordPress < 2.94.9 - Contributor+ Stored XSSEPSS 0.5%CVE-2025-2162MEDIUMMapPress Maps for WordPress < 2.94.10 - Admin+ Stored XSSEPSS 0.4%CVE-2024-8620MEDIUMMapPress Maps for WordPress < 2.93 - Admin+ Stored XSS via Map SettingsEPSS 0.3%