The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retrieve via an AJAX action is a public map, allowing unauthenticated users to read arbitrary private and draft posts.
CVE ID: CVE-2024-0421
Vendor: Unknown
Product: MapPress Maps for WordPress
EPSS Score: 0.38% (probability of being exploited)
EPSS Percentile: 58.72% (scored less or equal to compared to others)
EPSS Date: 2025-06-05 (when was this score calculated)
SSVC Exploitation: poc
SSVC Technical Impact: partial
SSVC Automatable: false