CVE-2026-56011 is an unauthenticated cross-site scripting (XSS) vulnerability affecting MapPress Maps for WordPress versions up to and including 2.97.3. Based on the provided content, the flaw allows attacker-controlled script to be injected and executed in a victim's browser without requiring authentication. Specific vulnerable parameters, code paths, or functions were not provided in the available information.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small local reproduction lab for CVE-2026-56011 affecting the MapPress Maps for WordPress plugin. It is not an automated exploit toolkit and contains no standalone exploit script; instead, it provisions two Dockerized WordPress environments for side-by-side validation: a vulnerable instance using MapPress 2.97.3 and a patched instance using 2.97.4. The core exploit capability demonstrated is unauthenticated web-based XSS through the `mappress=embed` iframe rendering path, where a crafted `name` parameter is injected into an unquoted `id` attribute in the vulnerable version, enabling attribute breakout and execution of JavaScript via an injected `onclick` handler. The provided payload is a manual browser PoC using `alert(1)`, requiring user interaction (clicking the rendered component) to trigger execution. Repository structure is minimal: `README.md` documents the vulnerability, validation steps, and expected behavior; `docker-compose.yml` orchestrates MariaDB, vulnerable/patched WordPress containers, and WP-CLI setup containers; `vuln/Dockerfile` and `patched/Dockerfile` build WordPress images that download and install specific MapPress plugin versions from WordPress.org. There are no external callback servers, persistence mechanisms, credential theft routines, or post-exploitation features. Overall, this is a controlled comparison lab and proof-of-concept environment for validating the XSS condition and confirming the patch behavior.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.