Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-56011-Lab — Docker-based lab for reproducing and validating CVE-2026-56011, an unauthenticated XSS vulnerability in MapPress Maps for WordPress, with vulnerable and patched comparison targets. | Kitploit
Tools/GitHubGitHub/rootdirective-sec/cve-2026-56011-lab
Vulnerability AnalysisWeb Application ExploitationWeb SecurityPenetration TestingLearning & EducationLabs & Practice
GitHubrootdirective-sec/cve-2026-56011-lab

CVE-2026-56011-Lab

Docker-based lab for reproducing and validating CVE-2026-56011, an unauthenticated XSS vulnerability in MapPress Maps for WordPress, with vulnerable and patched comparison targets.

View Repository
243 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-56011 - MapPress Maps for WordPress Unauthenticated XSS in iframe map rendering

Executive Summary

This repository contains a local Docker lab for reproducing and validating CVE-2026-56011, an unauthenticated Cross-Site Scripting vulnerability affecting MapPress Maps for WordPress.

MapPress Maps for WordPress is a WordPress plugin used to render maps inside WordPress pages and posts. The vulnerable behavior affects the iframe map rendering path that is reachable through the mappress=embed request parameter.

This lab compares two MapPress versions:

ServiceMapPress versionPurposeURL
vuln2.97.3Vulnerable comparison targethttp://localhost:8081
patched2.97.4Patched comparison targethttp://localhost:8082

The demonstrated validation path in this local lab is:

Unauthenticated browser request
→ GET /?mappress=embed
→ request supplies a crafted name value
→ vulnerable target renders name into an unquoted id attribute
→ injected onclick handler becomes a standalone HTML attribute
→ clicking the rendered MapPress component triggers alert(1)
→ patched target keeps the payload inside a quoted and escaped id attribute
→ clicking the rendered component does not trigger alert(1)

The vulnerable target uses this manual browser URL:

http://localhost:8081/?mappress=embed&name=cve56011%20onclick%3Dalert%281%29&width=400px&height=300px&zoom=5&center=0%2C0

Expected vulnerable result:

Click on the rendered MapPress component
→ alert(1) pops up

The patched target uses the same payload against MapPress 2.97.4:

http://localhost:8082/?mappress=embed&name=cve56011%20onclick%3Dalert%281%29&width=400px&height=300px&zoom=5&center=0%2C0

Expected patched result:

Click on the rendered MapPress component
→ no alert appears

This lab intentionally uses manual browser validation only. It does not include a PoC script, browser automation, credential theft, external callbacks, malware, persistence, post-exploitation activity, or attacks against external systems.

Verified Facts

ClaimEvidenceHow to verify in this lab
CVE-2026-56011 affects MapPress Maps for WordPress.Public vulnerability advisories identify the affected WordPress plugin as MapPress Maps for WordPress.Review the References section and inspect the plugin installed in both Docker targets.
The vulnerable comparison version in this lab is MapPress 2.97.3.The vuln service builds the plugin using MAPPRESS_VERSION: 2.97.3.Inspect docker-compose.yml and vuln/Dockerfile.
The patched comparison version in this lab is MapPress 2.97.4.The patched service builds the plugin using MAPPRESS_VERSION: 2.97.4.Inspect docker-compose.yml and patched/Dockerfile.
MapPress 2.97.4 introduced the relevant iframe escaping fix.The official plugin changelog for 2.97.4 says Added: escape in iframe.Review the official WordPress plugin changelog and compare the vulnerable and patched source.
The vulnerable source renders the map name into the web component id without quotes.In 2.97.3, mappress_map.php renders <mappress-map id={$name} ...>.Compare the 2.97.3 source with the 2.97.4 source.
The patched source quotes and escapes the id value.In 2.97.4, mappress_map.php renders id=" with esc_attr($name).Compare the patch diff between 2.97.3 and 2.97.4.
The iframe path is reachable without authentication.MapPress registers template_redirect when $_GET['mappress'] is present.Request /?mappress=embed... from a browser without logging in.
The iframe path reads map attributes from the request.template_redirect() maps $_GET into map arguments and calls the iframe renderer.Inspect mappress.php and reproduce the manual URL.
The vulnerable target allows attribute injection through name.The crafted name value can break out of the unquoted id attribute and become onclick=alert(1).Open the vulnerable manual URL and click the rendered MapPress component.
The patched target blocks the tested attribute injection behavior.The patched output keeps the full payload inside the quoted id attribute.Open the patched manual URL and click the rendered MapPress component.

Assumptions and Unknowns

This lab uses MapPress 2.97.3 as the vulnerable comparison target because public advisories identify versions up to and including 2.97.3 as affected, and the source diff shows the vulnerable unquoted attribute rendering in that version.

This lab uses MapPress 2.97.4 as the patched comparison target because public advisories identify 2.97.4 as the fixed version, and the official changelog states that escaping was added in the iframe path.

The tested vulnerable behavior is the unauthenticated iframe rendering path:

GET /?mappress=embed&name=<crafted-value>

This lab focuses on manual browser execution of a harmless alert payload:

name=cve56011 onclick=alert(1)

The lab does not attempt to prove a stored delivery chain. Some public advisories classify the vulnerability as stored XSS. This repository focuses on the source-confirmed iframe rendering sink and the vulnerable-versus-patched behavior that can be reproduced locally through the unauthenticated mappress=embed route.

The lab does not demonstrate:

  • stored payload persistence,
  • WordPress account compromise,
  • admin session theft,
  • nonce theft,
  • external callbacks,
  • blind XSS collection,
  • credential theft,
  • database dumping,
  • malware,
  • persistence,
  • or attacks against non-lab systems.

The manual browser validation proves the security-relevant rendering difference:

MapPress 2.97.3:
  crafted name value becomes executable onclick attribute

MapPress 2.97.4:
  crafted name value remains inside the quoted id attribute

Root Cause Summary

The root cause of CVE-2026-56011 is incorrect output encoding for the map name value when MapPress renders a web component inside the iframe map output path.

The vulnerable code path accepts map rendering attributes from the request and eventually renders a custom HTML element:

<mappress-map ...>

In MapPress 2.97.3, the map name is inserted directly into the id attribute without quotes and without attribute-context escaping:

return "<div></div>\r\n<mappress-map id={$name} {$atts}>\r\n$pois\r\n</mappress-map>\r\n";
Download Tool