INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

CVE-2026-8732: WP Maps Pro Flaw Allows Anyone to Admin

| 2026-06-01 08:45 CRITICAL HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The vulnerability, CVE-2026-8732, in the WP Maps Pro plugin has been identified as a critical technical issue that allows unauthenticated attackers to create WordPress admin accounts. The vulnerability is tracked by the Mitre ATT&CK technique of privilege escalation and can be exploited through an AJAX action called wpgmp_temp_access_ajax, which can be registered with wp_ajax_nopriv_ and protected only by a nonce check. This makes it possible for unauthenticated attackers to invoke the handler with check_temp=false, creating a new WordPress user with hardcoded administrator role. The vulnerability has been reported on over 15,000 websites using Envato Market sales data, indicating widespread impact.
Technical Mitigations AI-generated
* Implement nonce-based authentication: Ensure that the WordPress admin login process uses a nonce (a unique value) to prevent cross-site request forgery attacks. This can be achieved by using a secure random number generator and verifying the nonce on each request. * Use secure JavaScript execution: Use a reputable JavaScript engine like WebKit or Blink, which have built-in security features such as sandboxing and memory protection, to execute WordPress scripts. * Disable publicly accessible endpoints: Remove any publicly accessible endpoints in the WP Maps Pro plugin that could be exploited by attackers. This includes removing the "wpgmp_temp_access_ajax" endpoint from the JavaScript code. * Implement rate limiting on admin login attempts: Implement a rate limiter on the admin login process to prevent brute-force attacks and limit the number of login attempts within a certain time frame. * Use secure communication protocols (e.g. HTTPS): Ensure that all communication between WordPress and the plugin is encrypted using HTTPS, which will help protect against eavesdropping and man-in-the-middle attacks.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

su•••@fl•••.•••
fl•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-8732CVE-2026-8732
Target & Sectors
Global Scope
Incident Timeline
‎March 24
Brown reported the flaw to Wordfence on March 24, and the vendor validated it as exploitable on May 16.
organisation Wordfence
‎May 16
Wordfence's vendor validated the exploit for actively exploited Critical WP Maps Pro flaw on May 16.
organisation Wordfence
‎May 20, 2026
The vulnerability was exploited to create admin accounts on the affected WordPress Maps Pro plugin.
infrastructure 6.1.1
‎May 20
The threat actors exploited a previously unknown vulnerability (CVE-2026-8732) in WP Maps Pro 6.1.1 to gain unauthorized access and create admin accounts on affected systems.
vulnerability CVE-2026-8732
infrastructure 6.1.1
‎Jun 01, 2026
The threat actors exploited a privilege escalation bug in WordPress Maps Pro, CVE-2026-8732, allowing them to create admin accounts by exploiting the wpgmp_temp_access_support AJAX action.
infrastructure 6.1.0
infrastructure 6.1.1
organisation Google Maps
organisation AJAX
organisation wpgmp_temp_access_support
‎2026/06/01
Threat actors are attempting to actively exploit a critical security flaw in WP Maps Pro, a WordPress plugin with over 15,000 sales on Envato Market.
organisation WordPress
organisation CVSS
infrastructure 6.1.0
infrastructure 6.1.1
organisation Pro Flaw Actively Exploited
organisation Vulnerability / Website Security
organisation Envato Market
organisation Google Maps
organisation AJAX
organisation wpgmp_temp_access_ajax
organisation wpgmp_temp_access_support
organisation SecurityAffairs
Tactical Metrics
Metrics
infrastructure
‎6.1.0
Software Version
Metrics
infrastructure
‎6.1.1
Software Version