A critical vulnerability in the WP Maps Pro WordPress plugin is being actively exploited to let unauthenticated attackers create administrator accounts and fully take over affected websites. The flaw, tracked as CVE-2026-8732 and rated CVSS 9.8, affects versions through 6.1.0 and was discovered by Wordfence through its bug bounty program. Researchers said the issue stems from improper privilege validation in the plugin’s temporary support-access feature, where the wpgmp_temp_access_ajax_callback() endpoint was exposed to unauthenticated users and protected only by a publicly accessible nonce.
Successful exploitation allows an attacker to trigger backend admin account creation, obtain a secret or magic login URL, and sign in without a password. Wordfence reported blocking 2,514 attacks in 24 hours, indicating rapid automated exploitation in the wild, and said roughly 15,000 WordPress sites are affected. The vendor has released a fix in WP Maps Pro 6.1.1 by adding a capability check that restricts access to users with manage_options, while Wordfence said firewall protection was issued to premium customers on May 18 and scheduled for free users on June 17.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Wordfence said users on its free tier were scheduled to receive firewall protection for the WP Maps Pro vulnerability on 2026-06-17. This was presented as the delayed rollout date for non-premium customers.
A newer report said Wordfence blocked 2,858 exploitation attempts targeting CVE-2026-8732 in the previous 24 hours. This reflects continued active exploitation of the WP Maps Pro administrator account creation flaw after public disclosure.
Wordfence reported that it blocked 2,514 attacks targeting the WP Maps Pro vulnerability within a 24-hour period. This indicated rapid automated exploitation following discovery of the flaw.
Wordfence disclosed CVE-2026-8732, a critical WP Maps Pro vulnerability that lets unauthenticated attackers create administrator accounts and take over affected WordPress sites. The advisory said the bug was being actively exploited in the wild and that roughly 15,000 sites were affected.
The WP Maps Pro vendor released version 6.1.1 to fix the vulnerability by adding a capability check or restricting the vulnerable endpoint to users with the manage_options capability. The flaw affected versions up to and including 6.1.0.
Security Affairs reported that the WP Maps Pro maintainers fixed CVE-2026-8732 in version 6.1.1 released on 2026-05-20. The update addressed the flaw that allowed unauthenticated attackers to create administrator accounts on sites running versions up to 6.1.0.
Wordfence said its premium customers received firewall protection for CVE-2026-8732 on 2026-05-18. The protection addressed the WP Maps Pro vulnerability that allows unauthenticated administrator account creation.
After receiving David Brown's report, Wordfence notified the WP Maps Pro vendor about the administrator account creation flaw later tracked as CVE-2026-8732. This vendor notification preceded the release of version 6.1.1 that fixed the issue.
Researcher David Brown reported the WP Maps Pro administrator account creation vulnerability to the Wordfence Bug Bounty Program. The report initiated coordinated disclosure of the flaw later tracked as CVE-2026-8732.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcethecyberexpress.com
Open sourcecvefeed.io
Open sourcesecurityonline.info
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.