WP Maps Pro WordPress flaw exploited to create admin accounts


TL;DR

A critical vulnerability (CVE-2026-8732, CVSS 9.8) in the WP Maps Pro WordPress plugin allows unauthenticated attackers to create admin accounts and take over sites. Wordfence blocked 2,858 exploitation attempts in 24 hours, with the flaw patched in version 6.1.1.

A critical vulnerability in WP Maps Pro, a commercial WordPress plugin with more than 15,000 sales on the Envato Market, is being actively exploited by attackers to create malicious administrator accounts on vulnerable sites. The flaw, tracked as CVE-2026-8732 with a CVSS score of 9.8, allows unauthenticated users to gain full administrative control of any WordPress installation running an unpatched version of the plugin.

Wordfence, which discovered the exploitation campaign, reported blocking 2,858 attacks targeting the vulnerability in the 24 hours prior to its disclosure. The flaw affects all versions of WP Maps Pro up to and including 6.1.0 and was patched in version 6.1.1, released on 20 May 2026. Security researcher David Brown is credited with discovering and reporting the issue.

How the exploit works

WP Maps Pro includes a “temporary access” feature designed to let the plugin’s support staff log into a customer’s site during troubleshooting. The feature exposes an AJAX action called “wpgmp_temp_access_ajax” that can create a new WordPress user with administrator privileges. The security architecture behind the feature was fundamentally flawed: the action was registered with WordPress’s “wp_ajax_nopriv_” hook, meaning it could be called by unauthenticated visitors.

The only protection was a nonce check, a token meant to prevent cross-site request forgery. But the nonce was publicly embedded into every frontend page of the site via the “wpgmp_local” JavaScript object, rendering it useless as an access control mechanism. Any visitor could read the nonce from the page source and use it to invoke the function.

The 💜 of EU tech

The latest rumblings from the EU tech scene, a story from our wise ol’ founder Boris, and some questionable AI art. It’s free, every week, in your inbox. Sign up now!

An attacker who calls the endpoint with the parameter “check_temp=false” triggers the “wpgmp_temp_access_support()” function, which unconditionally creates a new WordPress user with the hardcoded role of administrator and returns a magic login URL. Visiting that URL calls “wp_set_auth_cookie()” to fully authenticate the attacker as the newly created admin. The entire chain, from unauthenticated request to full site takeover, requires no credentials, no social engineering, and no prior access.

The plugin and its reach

WP Maps Pro allows site owners to embed customisable Google Maps and OpenStreetMap views with markers, listings, and advanced location features. It is commonly used as a store locator tool for businesses that need to help users find nearby locations, view details, and get directions. The plugin is sold through the Envato Market (CodeCanyon), not through WordPress’s official plugin directory, which means updates are not distributed through the standard WordPress auto-update mechanism.

That distribution model creates a particular risk. Site owners who purchased the plugin may not receive automatic notifications about the security update, and many WordPress installations are maintained by non-technical users or agencies that do not monitor vulnerability disclosures. Unlike large-scale cybercrime infrastructure that law enforcement can target with server seizures, WordPress plugin vulnerabilities are exploited through distributed, automated scanning campaigns that are difficult to disrupt.

What site owners should do

The patch in version 6.1.1 restricts the temporary access endpoint to authenticated administrators only. Site owners running WP Maps Pro should update immediately. Those who cannot update should disable the plugin until they can apply the patch. Checking for unexpected administrator accounts in the WordPress user list is a practical first step to determine whether a site has already been compromised.

The vulnerability is a textbook example of a pattern that recurs across the WordPress ecosystem: a support or debugging feature that grants elevated privileges, protected by a security mechanism that does not actually restrict access. Vulnerability disclosure programmes and security researchers like Brown play a critical role in catching these flaws before they cause widespread damage, but the 2,858 attacks blocked in a single day demonstrate that the window between disclosure and exploitation is now measured in hours, not weeks.



Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Tommiee lost both parents when he was young and grew up in the care system, moving between different families and situations. These early experiences followed him into adulthood – he often felt like he didn’t belong, and ongoing housing challenges meant he never had a true sense of security. Despite everything, he held onto hope, and he found community in places where he felt understood, like the skate park in Bedminster.

In this interview with senior support worker, Fisayo, Tommiee reflects on his journey and how meeting Second Step helped him finally find stability after a lifetime of instability.

Dean Lane skate park, near North Street in Bedminster, has been a cornerstone of Bristol’s skate community for decades. Since opening in 1978, it has served generations of skaters and become a much‑loved fixture of the neighbourhood.

“Sharing a space like this, you know, I feel like for a lot of people that don’t want to be at home, or have difficulties inside or with themselves, or interacting with people, it’s a place where you can come,” says Tommiee, “It’s like an outdoor mental health men’s club. So having the opportunity to come back here, even though I don’t live here anymore now, is good, you know?”

Although he doesn’t live in Bedminster anymore, Tommiee came back to the skate park to meet his support worker, Fisayo, and tell his story:

Tommiee: “My name is Tom – Tommiee Mosarey – also known as BS3 Chase. I came to Second Step because I was probably going through a hard time in my life and I was having difficulty in my housing.”

Fisayo: “How has Second Step helped you? How’s your journey been so far?”

Tommiee: “They moved quickly. They actually listened to me, so I’m happy to be where I am now.”

Fisayo: “Do you want to tell a bit about your background and what you faced growing up till now?”

Tommiee: “Yeah, man. I faced a lot. I think everyone’s got a story to tell that would make you feel sad. But, obviously having to deal with that every day… My parents died when I was a baby. I was very young and obviously due to that I had to grow up in different situations, in different families, and yeah it was kind of hard.

“I was always me, if you know what I mean. I had to find me and then find out how I fit into society, you know.”

Fisayo: “What would you say is one thing that actually kept you going?”

Tommiee: “I guess my energy, my resilience, me wanting to have a happy ending, me knowing that it’s working out for this person over here, it’s working out for those people over there. I’m going to get my time soon, and it’s just waiting for the stars to align. Just waiting and being patient.

“I was actually going to give up before Second Step came, not give up but… let me explain this: before Second Step, it was like another house, another home, another group of people that I had to go and see and work with who were going to promise me my happy ending. And I had been failed up until then. And then obviously I met you guys. So I was a bit hesitant at first, and then obviously I met you and we sat down, we spoke, and we had similar interests. So I think that’s what made me grow to you and then, I don’t know, I just was like I trust you, you know? And then, I’m still here now, so it works out.”

Fisayo: “Do you find using a support worker helpful in any way?”

Tommiee: “I think Second Step try and pair you with somebody that you will actually resonate with. I learned how to open up and trust you about other things that I couldn’t do or I didn’t know I had to do that were the steps to take to get my own independence.

“So now I am, and my life’s changed. I got a new job, I live in a whole new area. It’s a lot of responsibilities but living in Second Step (Toll House Court) and taking that step initially and working with you, realising that good things can happen to all of us.

“Like I said at the beginning, everyone’s probably got a story to get you that’s probably going to make you feel sad, do you know what I mean? But it’s part of our movie. And even if you have no one and feel like you got no one, there’s always someone there. There’s always a service there. There’s always a person like you to help, that genuinely just wants to help another person. And when you’re human about it, it’s great and it works out.

“I’ve been through a lot of services, a lot of different things, you know, just growing up from a kid in the system, like a little baby into an adult. I feel like every single one of them services kind of let me down. But every single one of them was a step to find the right step for me, which was Second Step.

“And I feel like, especially the last seven years before I met you guys, being here in Bedminster and growing up and finding myself, it’s great on the outside, but my home life wasn’t great. I was living in shared houses with other people who had issues and problems and stuff like that. And if you do get the opportunity to get engaged with services like Second Step – really lucky. The person they’ve got to work with you, they’ll match you with someone that you know you’re comfortable with. They can see where you’re going wrong and then kind of point you in the right direction, you see what I’m saying? I feel like that’s what you’ve done for me really. I just hope that you’re proud of me, you know?

Fisayo: “Definitely. I’m proud of you. You made the right choice, you know, taking the right steps and we can only wish you the best. And just keep your head held high, keep it moving. So many dreams out there and so many things to achieve as well. Proud of you, man. Yeah, man, that’s good. Thank you.”

Thank you to Tommiee for sharing your story of hope and courage, and to Fisayo for the support and compassion that helped Tommiee along the way.

To find out more about the Second Step services and the support we offer please take a look at the Our Services section on our website.



Source link