CVE-2026-8935
The WP MAPS PRO WordPress plugin before version 6.1.1 allows unauthenticated attackers to create administrator accounts and gain full admin access via a magic-login URL by exploiting a vulnerable AJAX action that accepts valid nonces from frontend pages.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of the WP MAPS PRO WordPress plugin version 6.1.0 or earlier
Real-world impact
Attackers could gain full administrative control of vulnerable WordPress sites without authentication, leading to data breaches or site compromise.
Why this severity
Critical (CVSS 9.8): High risk due to ease of exploitation and severe consequences of unauthorized admin access.
What to do about it
- ›Avoid using the WP MAPS PRO plugin until a patched version (6.1.1 or later) is available.
- ›If using the vulnerable version, restrict access to the plugin's AJAX endpoint or disable nonces on frontend pages.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No official fix documented in sources; mitigation based on vulnerability description.
Timeline
- Jun 15, 2026 · Jun 15, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.