WP Maps Pro Flaw Creates Unauthorized WordPress Admin Accounts
TL;DR. A critical vulnerability in the WP Maps Pro plugin allows hackers to create unauthorized administrator accounts on WordPress websites. - The flaw, CVE-2026-8732, affects versions 6.1.0 and older. - Attackers exploit a temporary access feature to generate admin logins without authentication. - Over 3,600 exploitation attempts were blocked within 24 hours of discovery.
- WP Maps Pro plugin vulnerability CVE-2026-8732 allows unauthenticated admin account creation.
- The flaw affects WordPress sites using plugin versions 6.1.0 and older.
- Threat actors are actively exploiting this vulnerability.
- Website administrators should update to WP Maps Pro 6.1.1 immediately.
Sources
- WP Maps Pro bug exploited to create admin accounts on WordPress sites — bleepingcomputer.com