WP Maps Pro’s “temporary access” feature breaks the normal trust boundary. A request that was meant for vendor troubleshooting can be used by anyone to create a new administrator account, so patching a site does not help once that account exists.
The flaw is CVE-2026-8732 in WP Maps Pro 6.1.0 and older. Researchers say the backend endpoint was reachable without authentication because it trusted a nonce check exposed in frontend JavaScript, and Defiant has already blocked more than 3,600 exploit attempts; WP Maps Pro 6.1.1 fixes it.
The risk is persistence. An attacker who gets in through this path can keep control as a legitimate WordPress admin, which makes ordinary password resets and lockouts the wrong response to the problem.