CVE-2026-8732
The WP Maps Pro plugin for WordPress has a flaw that lets anyone on the internet create a new administrator account without logging in. The vulnerability is triggered by an AJAX call that is publicly accessible and bypasses normal security checks. Once the account is created, the attacker can log in as an administrator and take full control of the site.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
WordPress sites that use the WP Maps Pro plugin, versions up to and including 6.1.0.
Real-world impact
An attacker can create a new administrator user, log in as that user, and then modify or delete content, install malicious plugins, steal data, or otherwise compromise the entire website.
Why this severity
The CVSS score of 9.8 reflects that the flaw requires no authentication, has no user interaction, and gives an attacker complete control over the system, affecting confidentiality, integrity, and availability.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- May 29, 2026 · May 29, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 14d agoAdvisory updatedThe NVD record was last revised.