Vulnary
← back to the feed
Critical· 9.8

CVE-2026-8935

The WP MAPS PRO WordPress plugin before version 6.1.1 allows unauthenticated attackers to create administrator accounts and gain full admin access via a magic-login URL by exploiting a vulnerable AJAX action that accepts valid nonces from frontend pages.

publishedJun 15, 2026
last modifiedJul 23, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
19th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 6, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Users of the WP MAPS PRO WordPress plugin version 6.1.0 or earlier

02

Real-world impact

Attackers could gain full administrative control of vulnerable WordPress sites without authentication, leading to data breaches or site compromise.

03

Why this severity

Critical (CVSS 9.8): High risk due to ease of exploitation and severe consequences of unauthorized admin access.

04

What to do about it

no official fix yet
interim mitigations
  • Avoid using the WP MAPS PRO plugin until a patched version (6.1.1 or later) is available.
  • If using the vulnerable version, restrict access to the plugin's AJAX endpoint or disable nonces on frontend pages.

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

No official fix documented in sources; mitigation based on vulnerability description.

05

Timeline

  1. Jun 15, 2026 · Jun 15, 2026
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 23, 2026 · 12d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
CVE-2026-8935: The WP MAPS PRO WordPress plugin before version 6.1.1 allows unauthent · Vulnary