CVE-2024-0421

The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retrieve via an AJAX action is a public map, allowing unauthenticated users to read arbitrary private and draft posts.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mappresspro:mappress_maps_for_wordpress:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2024-02-12 16:15

Updated : 2024-11-21 08:46


NVD link : CVE-2024-0421

Mitre link : CVE-2024-0421

CVE.ORG link : CVE-2024-0421


JSON object : View

Products Affected

mappresspro

  • mappress_maps_for_wordpress
CWE
CWE-639

Authorization Bypass Through User-Controlled Key