{ "id": "CVE-2024-0421", "sourceIdentifier": "contact@wpscan.com", "published": "2024-02-12T16:15:08.620", "lastModified": "2024-02-12T16:15:08.620", "vulnStatus": "Received", "descriptions": [ { "lang": "en", "value": "The MapPress Maps for WordPress plugin before 2.88.16 does not ensure that posts to be retrieve via an AJAX action is a public map, allowing unauthenticated users to read arbitrary private and draft posts." } ], "metrics": {}, "references": [ { "url": "https://wpscan.com/vulnerability/587acc47-1966-4baf-a380-6aa479a97c82/", "source": "contact@wpscan.com" } ] }