CVE-2026-65564 is a MEDIUM severity vulnerability with a CVSS score of 5.3. It is an Unauthenticated Sensitive Data Exposure issue affecting MapPress Maps for WordPress plugin versions up to 2.97.6. The vulnerability allows an attacker to access sensitive data without authentication, potentially leading to data exposure. WordPress users with MapPress Maps for WordPress plugin installed should be aware of [truncated]
The MapPress Maps for WordPress plugin, up to and including version 2.96.6, is vulnerable to Authorization Bypass Through User-Controlled Key. This vulnerability is due to missing ownership verification in the REST API routes registered via `Mappress_Api::rest_api_init()`. Specifically, the GET `/wp-json/mapp/v1/maps/{mapid}` endpoint uses `'permission_callback' => '__return_true'`, allowing unauthenticat [truncated]