INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
CVE-2026-8732: WP Maps Pro Flaw Allows Anyone to Admin
| 2026-06-01 08:45 CRITICAL HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The vulnerability, CVE-2026-8732, in the WP Maps Pro plugin has been identified as a critical technical issue that allows unauthenticated attackers to create WordPress admin accounts. The vulnerability is tracked by the Mitre ATT&CK technique of privilege escalation and can be exploited through an AJAX action called wpgmp_temp_access_ajax, which can be registered with wp_ajax_nopriv_ and protected only by a nonce check. This makes it possible for unauthenticated attackers to invoke the handler with check_temp=false, creating a new WordPress user with hardcoded administrator role. The vulnerability has been reported on over 15,000 websites using Envato Market sales data, indicating widespread impact.
Technical Mitigations AI-generated
* Implement nonce-based authentication: Ensure that the WordPress admin login process uses a nonce (a unique value) to prevent cross-site request forgery attacks. This can be achieved by using a secure random number generator and verifying the nonce on each request.
* Use secure JavaScript execution: Use a reputable JavaScript engine like WebKit or Blink, which have built-in security features such as sandboxing and memory protection, to execute WordPress scripts.
* Disable publicly accessible endpoints: Remove any publicly accessible endpoints in the WP Maps Pro plugin that could be exploited by attackers. This includes removing the "wpgmp_temp_access_ajax" endpoint from the JavaScript code.
* Implement rate limiting on admin login attempts: Implement a rate limiter on the admin login process to prevent brute-force attacks and limit the number of login attempts within a certain time frame.
* Use secure communication protocols (e.g. HTTPS): Ensure that all communication between WordPress and the plugin is encrypted using HTTPS, which will help protect against eavesdropping and man-in-the-middle attacks.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
su•••@fl•••.•••
fl•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-8732CVE-2026-8732
Target & Sectors
Global Scope
Incident Timeline
March 24
Brown reported the flaw to Wordfence on March 24, and the vendor validated it as exploitable on May 16.
Click on any entity below to view its context and source!
organisation
Wordfence
Brown reported the flaw to Wordfence on March 24, and the vendor was notified on May 16 after validating the exploit.
May 16
Wordfence's vendor validated the exploit for actively exploited Critical WP Maps Pro flaw on May 16.
Click on any entity below to view its context and source!
organisation
Wordfence
Brown reported the flaw to Wordfence on March 24, and the vendor was notified on May 16 after validating the exploit.
May 20, 2026
The vulnerability was exploited to create admin accounts on the affected WordPress Maps Pro plugin.
Click on any entity below to view its context and source!
infrastructure
6.1.1
The plugin maintainers addressed the issue on May 20, 2026, with the release of version 6.1.1.
May 20
The threat actors exploited a previously unknown vulnerability (CVE-2026-8732) in WP Maps Pro 6.1.1 to gain unauthorized access and create admin accounts on affected systems.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-8732
On May 20, WP Maps Pro 6.1.1 was released with a fix for CVE-2026-8732.
infrastructure
6.1.1
On May 20, WP Maps Pro 6.1.1 was released with a fix for CVE-2026-8732.
Jun 01, 2026
The threat actors exploited a privilege escalation bug in WordPress Maps Pro, CVE-2026-8732, allowing them to create admin accounts by exploiting the wpgmp_temp_access_support AJAX action.
Click on any entity below to view its context and source!
infrastructure
6.1.0
The shortcoming impacts all versions of the plugin prior to and including 6.1.0.
infrastructure
6.1.1
It has been addressed in version 6.1.1.
organisation
Google Maps
WP Maps Pro allows site owners to embed customizable Google Maps and OpenStreetMap with markers, listings, and advanced location features on WordPress sites.
organisation
AJAX
"This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce check using the fc-call-nonce nonce, which is publicly embedded into every frontend page via wp_localize_script as the nonce field of the wpgmp_local JavaScript object, rendering the check ineffective as an access control mechanism," Wordfence
said
.
organisation
wpgmp_temp_access_support
"This makes it possible for unauthenticated attackers to invoke the wpgmp_temp_access_support handler with check_temp=false, which unconditionally creates a new WordPress user with the hardcoded role of administrator via wp_insert_user() and returns a magic login URL that, when visited, calls wp_set_auth_cookie() to fully authenticate the attacker as the newly created administrator, resulting in complete site takeover.
2026/06/01
Threat actors are attempting to actively exploit a critical security flaw in WP Maps Pro, a WordPress plugin with over 15,000 sales on Envato Market.
Click on any entity below to view its context and source!
organisation
WordPress
The WP Maps Pro Flaw That Lets Anyone Create a WordPress Admin Without a Password.
CVE-2026-8732: The WP Maps Pro Flaw That Lets Anyone Create a WordPress Admin Without a Password
CVE-2026-8732 in WP Maps Pro lets unauthenticated attackers create WordPress admin accounts.
Ravie Lakshmanan
Jun 01, 2026
Vulnerability / Website Security,
Threat actors are attempting to actively exploit a critical security flaw impacting
WP Maps Pro
, a WordPress plugin that has had over 15,000 sales on the Envato Market, to create malicious administrator accounts on susceptible sites.
WP Maps Pro bug exploited to create admin accounts on WordPress sites.
organisation
CVSS
The vulnerability is tracked as CVE-2026-8732 and received a CVSS score of 9.8.
infrastructure
6.1.0
The vulnerability, tracked as CVE-2026-8732, has a critical severity rating and impacts WP Maps Pro versions 6.1.0 and older.
All versions up to and including 6.1.0 remain vulnerable.
infrastructure
6.1.1
If you’re running WP Maps Pro, update to 6.1.1 immediately.
organisation
Pro Flaw Actively Exploited
Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts.
organisation
Vulnerability / Website Security
Ravie Lakshmanan
Jun 01, 2026
Vulnerability / Website Security,
Threat actors are attempting to actively exploit a critical security flaw impacting
WP Maps Pro
, a WordPress plugin that has had over 15,000 sales on the Envato Market, to create malicious administrator accounts on susceptible sites.
organisation
Envato Market
The plugin is installed on over 15,000 websites, according to sale data of Envato Market.
organisation
Google Maps
WP Maps Pro plugin allows WordPress site owners to embed Google Maps and OpenStreetMap with markers, listings, and location search.
It supports multiple map providers, such as Google Maps and OpenStreetMap.
organisation
AJAX
That feature registered an AJAX action called wpgmp_temp_access_ajax using WordPress’s wp_ajax_nopriv_ hook, which means unauthenticated users can call it.
Brown found that the AJAX endpoint used for this feature was accessible to unauthenticated users and relied solely on a publicly exposed nonce check in frontend JavaScript, rendering the protection ineffective.
organisation
wpgmp_temp_access_ajax
That feature registered an AJAX action called wpgmp_temp_access_ajax using WordPress’s wp_ajax_nopriv_ hook, which means unauthenticated users can call it.
organisation
wpgmp_temp_access_support
“This makes it possible for unauthenticated attackers to invoke the wpgmp_temp_access_support handler with check_temp=false, which unconditionally creates a new WordPress user with the hardcoded role of administrator via wp_insert_user() and returns a magic login URL that, when visited, calls wp_set_auth_cookie() to fully authenticate the attacker as the newly created administrator, resulting in complete site takeover.”
organisation
SecurityAffairs
The cleanup after a full site takeover does not.
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, WordPress)
Tactical Metrics
Metrics
infrastructure
6.1.0
Software Version
Click for context!
The shortcoming impacts all versions of the plugin prior to and including 6.1.0.
All versions up to and including 6.1.0 remain vulnerable.
The vulnerability, tracked as CVE-2026-8732, has a critical severity rating and impacts WP Maps Pro versions 6.1.0 and older.
Metrics
infrastructure
6.1.1
Software Version
It has been addressed in version 6.1.1.
The plugin maintainers addressed the issue on May 20, 2026, with the release of version 6.1.1.
If you’re running WP Maps Pro, update to 6.1.1 immediately.
On May 20, WP Maps Pro 6.1.1 was released with a fix for CVE-2026-8732.
Intelligence Sources
BleepingComputer
2026-05-31
The Hacker News
2026-06-01
Security Affairs
2026-06-01
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
11x
organisation
Identified Entity
Pro Flaw Actively Exploited
entity
5x
timeline
Temporal Reference
Jun 01, 2026
date
2x
infrastructure
Software Version
6.1.0
version
2x
general metric
Jun
1
jun
2x
general metric
Sales
15,000
sales
2x
general metric
Attacks
2,858
attacks
Contextual Telemetry
Context Block
8 METRICS
tactic
Cyber Operation Type
Privilege Escalation
tactic
vulnerability
Exploited CVE
CVE-2026-8732
cve
general metric
Score
10
score
tactic
MITRE ATT&CK Technique
T1059.007 - JavaScript
technique
general metric
Past Hours
24
past hours
vulnerability
CVSS Score
10
score
general metric
Attempts
3,600
attempts
general metric
Surfaces
6
surfaces
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.