CVE-2026-8732
CVSS 9.8 CRITICAL: the WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. EPSS 2% (78º percentile).
Vulnerabilità ed exploit · Attacco ad app web
La funzione “temporary access” di WP Maps Pro rompe il normale perimetro di fiducia. Una richiesta che doveva servire per la risoluzione dei problemi da parte del vendor può essere usata da chiunque per creare un nuovo account amministratore, quindi il patching di un sito non serve una volta che quell’account esiste.
3 fonti · 1 giu
CVSS 9.8 CRITICAL: the WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. EPSS 2% (78º percentile).
SecurityWeek
WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites
The security defect (CVE-2026-8732) allows unauthenticated attackers to create administrative accounts on the affected installations.
originaleThe Hacker News
Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts
CVE-2026-8732 lets attackers create admin accounts in WP Maps Pro; 2,858 attacks hit vulnerable sites in 24 hours, risking takeover.
originaleBleepingComputer
WP Maps Pro bug exploited to create admin accounts on WordPress sites
Hackers are targeting WordPress websites running a vulnerable version of the WP Maps Pro plugin, which allows creating rogue administrator accounts without authentication.
originalePart of the PlainSec briefing for 2026-05-31
Every edition of this story: L’accesso di supporto diventa una backdoor admin di WordPress