Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3192 articles · 168075 vulns · 37/41 feeds (7d)
← Back to list
7.1
CVE-2026-56011KEVEXPLOITED
mappress · mappress maps for wordpress

WordPress MapPress Maps for WordPress plugin <= 2.97.3 - Cross Site Scripting (XSS) vulnerability

Description

Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.

Affected Products

VendorProductVersions
mappressmappress maps for wordpressn/a

References

  • https://patchstack.com/database/wordpress/plugin/mappress-google-maps-for-wordpress/vulnerability/wordpress-mappress-maps-for-wordpress-plugin-2-97-3-cross-site-scripting-xss-vulnerability?_s_id=cve(vdb-entry)

Related News (1 articles)

Tier C
VulDB1d ago
CVE-2026-56011 | chrisvrichardson MapPress Maps Plugin up to 2.97.3 on WordPress cross site scripting
→ No new info (linked only)
CVSS 3.17.1 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
CISA KEV✅ Yes
Actively exploited✅ Yes
CWECWE-79
PublishedJun 26, 2026
Last enriched1d agov2
Trending Score81
Source articles1
Independent1
Info Completeness9/14
Missing: epss, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (1)

MEDIUMCVE-2026-8839EXP
MapPress Maps for WordPress <= 2.96.6 - Unauthenticated Insecure Direct Object Reference via REST API Endpoints
Trending: 2

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 26, 2026
Added to CISA KEV
Jun 26, 2026
Discovered by ZDM
Jun 26, 2026
Updated: description
Jun 26, 2026
Actively Exploited
Jun 26, 2026

Version History

v2
Last enriched 1d ago
v2Tier C1d ago

Updated description with more technical detail and corrected exploit availability to false.

description
via VulDB
v11d ago

Initial creation