CVE-2026-14839
HIGHMapster WP Maps < 1.24.0 - Unauthenticated Private and Draft Post Content Disclosure
Title source: cnaDescription
The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status check on a public REST endpoint, allowing unauthenticated users to retrieve the title and full content of any post regardless of its status, including unpublished (draft, pending, private, and trashed) posts.
References (1)
Core 1
Core References
Exploit exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/1994e67d-5fdc-445f-a09d-2b25d2b2f445/
Scores
CVSS v3
7.5
EPSS
0.0026
EPSS Percentile
17.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (1)
None/Mapster WP Maps
< 1.24.0
Published
Aug 01, 2026
Tracked Since
Aug 01, 2026