Vulnerabilities & Exploits · Web App Attack

Support Access Becomes a WordPress Admin Backdoor

WP Maps Pro’s “temporary access” feature breaks the normal trust boundary. A request that was meant for vendor troubleshooting can be used by anyone to create a new administrator account, so patching a site does not help once that account exists.

The flaw is CVE-2026-8732 in WP Maps Pro 6.1.0 and older. Researchers say the backend endpoint was reachable without authentication because it trusted a nonce check exposed in frontend JavaScript, and Defiant has already blocked more than 3,600 exploit attempts; WP Maps Pro 6.1.1 fixes it.

The risk is persistence. An attacker who gets in through this path can keep control as a legitimate WordPress admin, which makes ordinary password resets and lockouts the wrong response to the problem.

3 sources · Jun 1

CVE-2026-8732

NVD KEV

CVSS 9.8 CRITICAL: the WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. EPSS 23% (98th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-06-01

Every edition of this story: Support Access Becomes a WordPress Admin Backdoor