CVE-2026-14839

HIGH

Mapster WP Maps < 1.24.0 - Unauthenticated Private and Draft Post Content Disclosure

Title source: cna
STIX 2.1

Description

The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status check on a public REST endpoint, allowing unauthenticated users to retrieve the title and full content of any post regardless of its status, including unpublished (draft, pending, private, and trashed) posts.

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/1994e67d-5fdc-445f-a09d-2b25d2b2f445/

Scores

CVSS v3 7.5
EPSS 0.0026
EPSS Percentile 17.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
None/Mapster WP Maps < 1.24.0
Published Aug 01, 2026
Tracked Since Aug 01, 2026