Sceawere
Vulnerability Detail
CVE-2026-39720UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated XSS in Mapster WP Maps
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 16h ago
- Vendor
- mapster
- Product
- Mapster WP Maps
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in Mapster WP Maps <= 2.0.4 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-06T09:17:44.227Z",
"pubdate": "2026-10-06T09:17:44.227Z",
"executiveSummary": "Mapster WP Maps versions 2.0.4 and below are susceptible to an unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This security flaw allows remote, unauthenticated attackers to inject malicious JavaScript payloads into the application, which are then executed within the browser context of unsuspecting users, including administrative personnel.\nThe vulnerability arises from improper neutralization of user-supplied input before rendering it in the browser. Successful exploitation poses significant risks, including the potential for unauthorized session hijacking, theft of sensitive authentication cookies, or the manipulation of the document object model (DOM) to facilitate phishing or drive-by downloads. Because the attack does not require authentication, the exploit surface is broad, allowing any visitor to the site to trigger the malicious code. The impact is elevated if an administrator views the injected payload, potentially leading to full site compromise, account takeover, or the persistent modification of site content. Organizations utilizing Mapster WP Maps are at elevated risk until the input handling mechanisms are properly sanitized.",
"technicalDetails": "The vulnerability is identified as a Stored Cross-Site Scripting (XSS) issue resulting from the failure to perform adequate input sanitization and output encoding on user-controllable data fields within the Mapster WP Maps plugin. The affected versions (<= 2.0.4) fail to validate data passed to the server, allowing an attacker to supply arbitrary HTML and script tags.\nThe exploitation flow typically involves the attacker identifying a vulnerable input field—often associated with map markers, labels, or configuration parameters—that is rendered on the frontend or within the WordPress administrative dashboard. By submitting a crafted HTTP request containing malicious payload vectors (such as <script>alert('XSS')</script> or obfuscated JavaScript), the attacker succeeds in storing the payload in the underlying database.\nWhen a legitimate user, such as a site administrator or a regular visitor, navigates to the page where the Mapster WP Maps component is rendered, the plugin retrieves the malicious payload from the database and inserts it directly into the HTML output without adequate escaping. The browser interprets the injected script as legitimate code originating from the trusted domain. Because the execution occurs within the context of the vulnerable origin, the script gains access to the user's cookies, local storage, and session tokens. Furthermore, the script can perform unauthorized actions on behalf of the victim using the application's current credentials, a mechanism commonly referred to as Cross-Site Request Forgery (CSRF) via XSS.\nThe technical root cause is a deficiency in the application's sanitization layer. Specifically, the component fails to utilize WordPress-native sanitization functions such as 'sanitize_text_field()' or 'esc_html()'/'esc_attr()' when processing and rendering data. The network exposure is total, as the plugin functionality is exposed publicly to any unauthenticated client interacting with the site. The attack does not require any specific privilege level, meaning the attacker can execute the exploit from an external network without a pre-existing account on the WordPress installation. Post-exploitation, an attacker might leverage the victim's session to elevate privileges, inject backdoors into themes or plugins, or redirect traffic to malicious external domains."
}