{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/arbitrary-meta-write/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mapster:wp_maps:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-12954"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WP Maps (\u003c= 1.23.0)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","wordpress","arbitrary-meta-write"],"_cs_type":"advisory","_cs_vendors":["Mapster"],"content_html":"\u003cp\u003eThe Mapster WP Maps plugin for WordPress, in versions up to and including 1.23.0, is susceptible to an arbitrary user meta write vulnerability. The flaw resides within the \u003ccode\u003emy_profile_update()\u003c/code\u003e function, which fails to implement necessary security controls, including nonce verification, capability checks, and allowlist validation for meta keys.\u003c/p\u003e\n\u003cp\u003eAn attacker with authenticated access (Subscriber-level or higher) can exploit this by submitting a crafted POST request containing the \u003ccode\u003eacf-photo-gallery-groups\u003c/code\u003e parameter. Because the plugin processes this input without validating the meta key or its associated value before executing the \u003ccode\u003eupdate_user_meta()\u003c/code\u003e function, an attacker can modify arbitrary user metadata fields. While the vulnerability does not directly facilitate privilege escalation, it can be leveraged to manipulate user profile data, potentially leading to unauthorized information modification or secondary impacts on account security depending on how other plugins or themes utilize user meta. Defenders should prioritize updating to the latest secure version once available.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability affects all users running Mapster WP Maps version 1.23.0 and earlier. Successful exploitation allows an authenticated attacker with minimal privileges (Subscriber) to modify arbitrary user metadata within the WordPress database. This can lead to account manipulation, potential data corruption, or the alteration of security-sensitive metadata used by other WordPress plugins, impacting the integrity of user accounts across the platform.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor WordPress server logs for anomalous POST requests directed at the plugin endpoints associated with profile updates, specifically monitoring for the \u003ccode\u003eacf-photo-gallery-groups\u003c/code\u003e parameter in requests originating from low-privileged user accounts.\u003c/li\u003e\n\u003cli\u003eAudit user metadata changes for unauthorized modifications occurring via the identified plugin function until an official patch is applied.\u003c/li\u003e\n\u003cli\u003eUpdate the Mapster WP Maps plugin to the latest version as soon as a patch is released by the vendor to remediate the missing authorization and validation logic.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T10:04:55Z","date_published":"2026-09-18T10:04:55Z","id":"https://feed.craftedsignal.io/briefs/2026-09-mapster-wp-maps-vuln/","summary":"The Mapster WP Maps WordPress plugin contains an arbitrary user meta write vulnerability via the my_profile_update() function, allowing authenticated users with Subscriber-level access to overwrite arbitrary user metadata.","title":"Arbitrary User Meta Write Vulnerability in Mapster WP Maps Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-mapster-wp-maps-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - Arbitrary-Meta-Write","version":"https://jsonfeed.org/version/1.1"}