A critical unauthenticated privilege escalation vulnerability (CVE-2026-8732, CVSS 9.8) in the WP Maps Pro WordPress plugin is being actively exploited. The flaw stems from a 'temporary access' support feature that registers an AJAX endpoint accessible to unauthenticated users via the wp_ajax_nopriv_ hook. The only protection — a nonce — was publicly exposed in every page's JavaScript, making it trivially bypassable. Attackers can call the endpoint to unconditionally create a new administrator account and receive a magic login URL, achieving full site takeover with no credentials required. Wordfence blocked 2,858 exploitation attempts within 24 hours of disclosure. The plugin, sold via Envato Market rather than the official WordPress directory, affects 15,000+ sites and lacks automatic update delivery. The flaw is patched in version 6.1.1. Site owners should update immediately, disable the plugin if unable to patch, and audit their WordPress user list for unexpected admin accounts.

4m read timeFrom thenextweb.com
Post cover image
Table of contents
How the exploit worksThe plugin and its reachWhat site owners should do
1 Impression