# WP Map Block <= 3.0.0 - Authenticated (Contributor+) Missing Authorization to Arbitrary Map Modification, Publication and Deletion

- **ID:** WPSEC-2026-0542
- **Plugin:** WP Map Block – Google Maps, OpenStreetMap, Mapbox, Store & Shop Locator, Directory, Listings & Filters (`wp-map-block`), https://wordpress.org/plugins/wp-map-block/
- **Affected versions:** from 3.0.0 before 3.1.0
- **Fixed in:** 3.1.0 (Update to 3.1.0 or later.)
- **Severity:** Medium 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-map-block
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0542/

## Description

The WP Map Block plugin for WordPress is vulnerable to unauthorized modification and loss of data via its map REST API endpoints in version 3.0.0. This is due to the create, update, delete, duplicate, status and bulk callbacks relying only on the generic 'edit_posts' capability, without per-map capability checks. This makes it possible for authenticated attackers, with Contributor-level access and above, to edit, duplicate, publish, unpublish or permanently delete any map, including maps owned by administrators, and to create published maps without the publish capability.

## References

- https://wpsec.com/vuln/WPSEC-2026-0542/
- https://plugins.svn.wordpress.org/wp-map-block/tags/3.1.0/
- https://wordpress.org/plugins/wp-map-block/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0542/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
