CVE-2026-8732
CVSS 9.8 CRITICAL: the WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. EPSS 23% (98th percentile).
Vulnerabilities & Exploits · Web App Attack
WP Maps Pro’s “temporary access” feature breaks the normal trust boundary. A request that was meant for vendor troubleshooting can be used by anyone to create a new administrator account, so patching a site does not help once that account exists.
The flaw is CVE-2026-8732 in WP Maps Pro 6.1.0 and older. Researchers say the backend endpoint was reachable without authentication because it trusted a nonce check exposed in frontend JavaScript, and Defiant has already blocked more than 3,600 exploit attempts; WP Maps Pro 6.1.1 fixes it.
The risk is persistence. An attacker who gets in through this path can keep control as a legitimate WordPress admin, which makes ordinary password resets and lockouts the wrong response to the problem.
3 sources · Jun 1
CVSS 9.8 CRITICAL: the WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. EPSS 23% (98th percentile).
SecurityWeek
WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites
The security defect (CVE-2026-8732) allows unauthenticated attackers to create administrative accounts on the affected installations.
originalThe Hacker News
Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts
CVE-2026-8732 lets attackers create admin accounts in WP Maps Pro; 2,858 attacks hit vulnerable sites in 24 hours, risking takeover.
originalBleepingComputer
WP Maps Pro bug exploited to create admin accounts on WordPress sites
Hackers are targeting WordPress websites running a vulnerable version of the WP Maps Pro plugin, which allows creating rogue administrator accounts without authentication.
originalPart of the PlainSec briefing for 2026-06-01
Every edition of this story: Support Access Becomes a WordPress Admin Backdoor