SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-14839

HIGH · CVSS 7.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

The Mapster WP Maps plugin for WordPress prior to version 1.24.0 is vulnerable due to a lack of authorization checks on a public REST endpoint, enabling unauthenticated users to access the titles and full content of all posts, including unpublished ones. This exposure could lead to unauthorized disclosure of sensitive or confidential information. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of data leakage.

CVE
CVE-2026-14839
Severity
HIGH
CVSS
7.5
EPSS
0.26%
WordPress

Original NVD Description

The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status check on a public REST endpoint, allowing unauthenticated users to retrieve the title and full content of any post regardless of its status, including unpublished (draft, pending, private, and trashed) posts.