What is CVE-2026-14839?
The Mapster WP Maps plugin for WordPress (versions prior to 1.24.0) contains an authorization bypass vulnerability on a public REST endpoint, enabling unauthenticated attackers to retrieve the title and full content of any post regardless of status, including unpublished drafts, private and trashed posts. Users should immediately update the plugin to version 1.24.0 or later to mitigate the risk.
Azərbaycanca: WordPress üçün Mapster WP Maps plaginində (1.24.0-dən əvvəlki versiyalar) müəyyən edilmiş CVE-2026-14839 zəifliyi ictimai REST endpoint-də avtorizasiya və post-status yoxlamasının olmaması səbəbindən autentifikasiya olunmamış istifadəçilərə istənilən yazının başlıq və tam məzmununu (qaralama, gizli, silinmiş daxil olmaqla) əldə etməyə imkan verir. Plagindən istifadə edən saytlar dərhal 1.24.0 və ya daha yüksək versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What plugin is affected by CVE-2026-14839 and what is its main impact?
The vulnerability is found in the Mapster WP Maps plugin for WordPress, in versions prior to 1.24.0. Due to a lack of authorization on a public REST endpoint, unauthenticated attackers can retrieve the title and full content of any post regardless of status, including unpublished drafts, private, and trashed posts.
What should users do to mitigate the risk of CVE-2026-14839?
Users should immediately update the Mapster WP Maps plugin to version 1.24.0 or later to mitigate the risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.