
Docker-based lab for reproducing and validating CVE-2026-56011, an unauthenticated XSS vulnerability in MapPress Maps for WordPress, with vulnerable and patched comparison targets.
This repository contains a local Docker lab for reproducing and validating CVE-2026-56011, an unauthenticated Cross-Site Scripting vulnerability affecting MapPress Maps for WordPress.
MapPress Maps for WordPress is a WordPress plugin used to render maps inside WordPress pages and posts. The vulnerable behavior affects the iframe map rendering path that is reachable through the mappress=embed request parameter.
This lab compares two MapPress versions:
| Service | MapPress version | Purpose | URL |
|---|---|---|---|
| vuln | 2.97.3 | Vulnerable comparison target | http://localhost:8081 |
| patched | 2.97.4 | Patched comparison target | http://localhost:8082 |
The demonstrated validation path in this local lab is:
Unauthenticated browser request
→ GET /?mappress=embed
→ request supplies a crafted name value
→ vulnerable target renders name into an unquoted id attribute
→ injected onclick handler becomes a standalone HTML attribute
→ clicking the rendered MapPress component triggers alert(1)
→ patched target keeps the payload inside a quoted and escaped id attribute
→ clicking the rendered component does not trigger alert(1)
The vulnerable target uses this manual browser URL:
http://localhost:8081/?mappress=embed&name=cve56011%20onclick%3Dalert%281%29&width=400px&height=300px&zoom=5¢er=0%2C0
Expected vulnerable result:
Click on the rendered MapPress component
→ alert(1) pops up
The patched target uses the same payload against MapPress 2.97.4:
http://localhost:8082/?mappress=embed&name=cve56011%20onclick%3Dalert%281%29&width=400px&height=300px&zoom=5¢er=0%2C0
Expected patched result:
Click on the rendered MapPress component
→ no alert appears
This lab intentionally uses manual browser validation only. It does not include a PoC script, browser automation, credential theft, external callbacks, malware, persistence, post-exploitation activity, or attacks against external systems.
| Claim | Evidence | How to verify in this lab |
|---|---|---|
| CVE-2026-56011 affects MapPress Maps for WordPress. | Public vulnerability advisories identify the affected WordPress plugin as MapPress Maps for WordPress. | Review the References section and inspect the plugin installed in both Docker targets. |
| The vulnerable comparison version in this lab is MapPress 2.97.3. | The vuln service builds the plugin using MAPPRESS_VERSION: 2.97.3. | Inspect docker-compose.yml and vuln/Dockerfile. |
| The patched comparison version in this lab is MapPress 2.97.4. | The patched service builds the plugin using MAPPRESS_VERSION: 2.97.4. | Inspect docker-compose.yml and patched/Dockerfile. |
| MapPress 2.97.4 introduced the relevant iframe escaping fix. | The official plugin changelog for 2.97.4 says Added: escape in iframe. | Review the official WordPress plugin changelog and compare the vulnerable and patched source. |
The vulnerable source renders the map name into the web component id without quotes. | In 2.97.3, mappress_map.php renders <mappress-map id={$name} ...>. | Compare the 2.97.3 source with the 2.97.4 source. |
The patched source quotes and escapes the id value. | In 2.97.4, mappress_map.php renders id=" with esc_attr($name). | Compare the patch diff between 2.97.3 and 2.97.4. |
| The iframe path is reachable without authentication. | MapPress registers template_redirect when $_GET['mappress'] is present. | Request /?mappress=embed... from a browser without logging in. |
| The iframe path reads map attributes from the request. | template_redirect() maps $_GET into map arguments and calls the iframe renderer. | Inspect mappress.php and reproduce the manual URL. |
The vulnerable target allows attribute injection through name. | The crafted name value can break out of the unquoted id attribute and become onclick=alert(1). | Open the vulnerable manual URL and click the rendered MapPress component. |
| The patched target blocks the tested attribute injection behavior. | The patched output keeps the full payload inside the quoted id attribute. | Open the patched manual URL and click the rendered MapPress component. |
This lab uses MapPress 2.97.3 as the vulnerable comparison target because public advisories identify versions up to and including 2.97.3 as affected, and the source diff shows the vulnerable unquoted attribute rendering in that version.
This lab uses MapPress 2.97.4 as the patched comparison target because public advisories identify 2.97.4 as the fixed version, and the official changelog states that escaping was added in the iframe path.
The tested vulnerable behavior is the unauthenticated iframe rendering path:
GET /?mappress=embed&name=<crafted-value>
This lab focuses on manual browser execution of a harmless alert payload:
name=cve56011 onclick=alert(1)
The lab does not attempt to prove a stored delivery chain. Some public advisories classify the vulnerability as stored XSS. This repository focuses on the source-confirmed iframe rendering sink and the vulnerable-versus-patched behavior that can be reproduced locally through the unauthenticated mappress=embed route.
The lab does not demonstrate:
The manual browser validation proves the security-relevant rendering difference:
MapPress 2.97.3:
crafted name value becomes executable onclick attribute
MapPress 2.97.4:
crafted name value remains inside the quoted id attribute
The root cause of CVE-2026-56011 is incorrect output encoding for the map name value when MapPress renders a web component inside the iframe map output path.
The vulnerable code path accepts map rendering attributes from the request and eventually renders a custom HTML element:
<mappress-map ...>
In MapPress 2.97.3, the map name is inserted directly into the id attribute without quotes and without attribute-context escaping:
return "<div></div>\r\n<mappress-map id={$name} {$atts}>\r\n$pois\r\n</mappress-map>\r\n";