CVE-2026-14839: Mapster WP Maps < 1.24.0 - Unauthenticated Private and Draft Post Content Disclosure
The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status check on a public REST endpoint, allowing unauthenticated users to retrieve the title and full content of any post regardless of its status, including unpublished (draft, pending, private, and trashed) posts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14839?
CVE-2026-14839 has a high severity rating of 7.5 according to the CVSS 3.1 standard.
How do I fix CVE-2026-14839?
To fix CVE-2026-14839, update the Mapster WP Maps plugin to version 1.24.0 or later.
What types of data are exposed due to CVE-2026-14839?
CVE-2026-14839 allows unauthenticated users to access the title and full content of posts, including unpublished drafts and private content.
Who is affected by CVE-2026-14839?
Users of the Mapster WP Maps plugin prior to version 1.24.0 are affected by CVE-2026-14839.
What is the exploitability of CVE-2026-14839?
CVE-2026-14839 is easily exploitable since it does not require authentication to access the affected REST endpoint.