Vulnerabilities / WP Map Block / WPSEC-2026-0542
WP Map Block <= 3.0.0 - Authenticated (Contributor+) Missing Authorization to Arbitrary Map Modification, Publication and Deletion
Medium 5.4
CWE-862Fixed in 3.1.0
- ID
- WPSEC-2026-0542
- Plugin
- WP Map Block – Google Maps, OpenStreetMap, Mapbox, Store & Shop Locator, Directory, Listings & Filters (wp-map-block)
- Affected
- from 3.0.0 before 3.1.0
- Remediation
- Update to 3.1.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
- Weakness
- CWE-862
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- WP Map Block on WPSec AttackSurface
- Fix released
- Published
Description
The WP Map Block plugin for WordPress is vulnerable to unauthorized modification and loss of data via its map REST API endpoints in version 3.0.0. This is due to the create, update, delete, duplicate, status and bulk callbacks relying only on the generic 'edit_posts' capability, without per-map capability checks. This makes it possible for authenticated attackers, with Contributor-level access and above, to edit, duplicate, publish, unpublish or permanently delete any map, including maps owned by administrators, and to create published maps without the publish capability.
References
- https://wpsec.com/vuln/WPSEC-2026-0542/
- https://plugins.svn.wordpress.org/wp-map-block/tags/3.1.0/
- https://wordpress.org/plugins/wp-map-block/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS