Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress
CVE-2026-65564

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 July 2026

What is CVE-2026-65564?

The MapPress Maps for WordPress plugin versions up to 2.97.6 have a vulnerability that allows unauthenticated users to access sensitive data. This flaw could potentially expose information that may facilitate unauthorized access or further exploitation. It is crucial for website owners using affected versions to assess their risk and apply the necessary updates to protect sensitive information from being compromised.

Affected Version(s)

MapPress Maps for WordPress <= 2.97.6

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
.