cleantalk
Vulnerabilities and Security Researches

MapPress Maps for WordPress, CVE-2025-2055

CVE, Research URL

CVE-2025-2055

Published on
Apr 03, 2025
Research Description
The MapPress Maps for WordPress plugin before 2.94.9 does not sanitise and escape some parameters when outputing them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.
Affected versions
Min -, max 2.94.9.
Status
vulnerable