Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityinternet-facing-service-vulnerabilitywidely-deployed-product-advisoryrapid-weaponization

Critical WP Maps Pro Flaw Lets Attackers Create WordPress Admin Accounts

Updated 21d agoFirst seen May 28, 202610 sources

A critical vulnerability in the WP Maps Pro WordPress plugin is being actively exploited to let unauthenticated attackers create administrator accounts and fully take over affected websites. The flaw, tracked as CVE-2026-8732 and rated CVSS 9.8, affects versions through 6.1.0 and was discovered by Wordfence through its bug bounty program. Researchers said the issue stems from improper privilege validation in the plugin’s temporary support-access feature, where the wpgmp_temp_access_ajax_callback() endpoint was exposed to unauthenticated users and protected only by a publicly accessible nonce.

Successful exploitation allows an attacker to trigger backend admin account creation, obtain a secret or magic login URL, and sign in without a password. Wordfence reported blocking 2,514 attacks in 24 hours, indicating rapid automated exploitation in the wild, and said roughly 15,000 WordPress sites are affected. The vendor has released a fix in WP Maps Pro 6.1.1 by adding a capability check that restricts access to users with manage_options, while Wordfence said firewall protection was issued to premium customers on May 18 and scheduled for free users on June 17.

Share:
Critical WP Maps Pro Flaw Lets Attackers Create WordPress Admin Accounts
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Jun 17, 20268d ago

Free Wordfence users scheduled to receive firewall protection

Wordfence said users on its free tier were scheduled to receive firewall protection for the WP Maps Pro vulnerability on 2026-06-17. This was presented as the delayed rollout date for non-premium customers.

15,000 WordPress Sites Affected by Administrator Account Creation Vulnerability in WP Maps Pro WordPress Plugin - Malware News - Malware Analysis, News and Indicators
Jun 1, 202624d ago

Wordfence reports blocking 2,858 WP Maps Pro exploit attempts in 24 hours

A newer report said Wordfence blocked 2,858 exploitation attempts targeting CVE-2026-8732 in the previous 24 hours. This reflects continued active exploitation of the WP Maps Pro administrator account creation flaw after public disclosure.

Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts
May 28, 202627d ago

Wordfence reports blocking 2,514 exploitation attempts in 24 hours

Wordfence reported that it blocked 2,514 attacks targeting the WP Maps Pro vulnerability within a 24-hour period. This indicated rapid automated exploitation following discovery of the flaw.

WP Maps Pro Vulnerability Exploited in the Wild

Wordfence discloses actively exploited WP Maps Pro zero-day

Wordfence disclosed CVE-2026-8732, a critical WP Maps Pro vulnerability that lets unauthenticated attackers create administrator accounts and take over affected WordPress sites. The advisory said the bug was being actively exploited in the wild and that roughly 15,000 sites were affected.

WP Maps Pro Vulnerability Exploited in the Wild

WP Maps Pro vendor fixes CVE-2026-8732 in version 6.1.1

The WP Maps Pro vendor released version 6.1.1 to fix the vulnerability by adding a capability check or restricting the vulnerable endpoint to users with the manage_options capability. The flaw affected versions up to and including 6.1.0.

WP Maps Pro Vulnerability Exploited in the Wild
May 20, 20261mo ago

Security Affairs reports WP Maps Pro 6.1.1 fix released

Security Affairs reported that the WP Maps Pro maintainers fixed CVE-2026-8732 in version 6.1.1 released on 2026-05-20. The update addressed the flaw that allowed unauthenticated attackers to create administrator accounts on sites running versions up to 6.1.0.

CVE-2026-8732: The WP Maps Pro Flaw That Lets Anyone Create a WordPress Admin Without a Password
May 18, 20261mo ago

Wordfence firewall protection released to premium users

Wordfence said its premium customers received firewall protection for CVE-2026-8732 on 2026-05-18. The protection addressed the WP Maps Pro vulnerability that allows unauthenticated administrator account creation.

15,000 WordPress Sites Affected by Administrator Account Creation Vulnerability in WP Maps Pro WordPress Plugin - Malware News - Malware Analysis, News and Indicators
May 16, 20261mo ago

Wordfence notifies WP Maps Pro vendor of CVE-2026-8732

After receiving David Brown's report, Wordfence notified the WP Maps Pro vendor about the administrator account creation flaw later tracked as CVE-2026-8732. This vendor notification preceded the release of version 6.1.1 that fixed the issue.

WP Maps Pro bug exploited to create admin accounts on WordPress sites
Mar 24, 20263mo ago

Researcher reports WP Maps Pro flaw to Wordfence Bug Bounty Program

Researcher David Brown reported the WP Maps Pro administrator account creation vulnerability to the Wordfence Bug Bounty Program. The report initiated coordinated disclosure of the flaw later tracked as CVE-2026-8732.

WP Maps Pro Flaw Exposed Sites To Administrator Takeover
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

14 LINKEDOpen in app
Affected products
3 linked
WordpressWordfenceOpenstreetmap
Organizations
10 linked
WordfenceEnvatoFlipper CodeEnvato MarketGoogleBleepingComputerGoDaddyThe Cyber ExpressSecurity AffairsWP Maps Pro
SOURCE COVERAGE

Sources

10 references tracked. Mallory keeps watching after this page renders.

10 SOURCESView all
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.