---
title: "WP Maps Pro WordPress flaw exploited to create admin accounts"
url: https://daily.dev/posts/wp-maps-pro-wordpress-flaw-exploited-to-create-admin-accounts-3jrka26ha
source_url: https://thenextweb.com/news/wp-maps-pro-wordpress-vulnerability-admin-accounts-cve-2026-8732
type: article
source: "The Next Web"
published: 2026-06-01T19:46:42.167Z
updated: 2026-06-01T19:47:27.494Z
tags: ["security", "wordpress"]
reading_time: 4
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# WP Maps Pro WordPress flaw exploited to create admin accounts

**[The Next Web](https://daily.dev/sources/tnw)** · 4 min read · 0 upvotes · 0 comments

## Summary

A critical unauthenticated privilege escalation vulnerability (CVE-2026-8732, CVSS 9.8) in the WP Maps Pro WordPress plugin is being actively exploited. The flaw stems from a 'temporary access' support feature that registers an AJAX endpoint accessible to unauthenticated users via the wp_ajax_nopriv_ hook. The only protection — a nonce — was publicly exposed in every page's JavaScript, making it trivially bypassable. Attackers can call the endpoint to unconditionally create a new administrator account and receive a magic login URL, achieving full site takeover with no credentials required. Wordfence blocked 2,858 exploitation attempts within 24 hours of disclosure. The plugin, sold via Envato Market rather than the official WordPress directory, affects 15,000+ sites and lacks automatic update delivery. The flaw is patched in version 6.1.1. Site owners should update immediately, disable the plugin if unable to patch, and audit their WordPress user list for unexpected admin accounts.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thenextweb.com/news/wp-maps-pro-wordpress-vulnerability-admin-accounts-cve-2026-8732>

## Similar posts on daily.dev

- [Critical Kirki flaw exploited to hijack WordPress admin accounts](https://daily.dev/posts/critical-kirki-flaw-exploited-to-hijack-wordpress-admin-accounts-ym6h9qcps) · BleepingComputer · 1 upvotes · 0 comments
- [WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts](https://daily.dev/posts/wordpress-king-addons-flaw-under-active-attack-lets-hackers-make-admin-accounts-90n2qv4qa) · The Hacker News · 3 upvotes · 0 comments
- [Critical WordPress Plugin Vulnerability Allows Unauthenticated Admin Takeover on 150K Sites](https://daily.dev/posts/critical-wordpress-plugin-vulnerability-allows-unauthenticated-admin-takeover-on-150k-sites-2ap9ez0hm) · Orca Security Blog · 2 upvotes · 2 comments

---

Tags: [#security](https://daily.dev/tags/security), [#wordpress](https://daily.dev/tags/wordpress)

[View this post on daily.dev](https://daily.dev/posts/wp-maps-pro-wordpress-flaw-exploited-to-create-admin-accounts-3jrka26ha)
