Security Alert: WP Maps Pro allows you to create administrator accounts without authentication (CVE-2026-8732)

Author: Published 4 min de lectura 172 reading

The images in this article were generated with artificial intelligence. How we publish

A critical failure in the premium WP Maps Pro plugin for WordPress has started to be exploited in nature and allows attackers to create administrator accounts without authentication, which turns sites with old versions of the plugin into high value targets. Vulnerability, recorded as CVE-2026-8732, affects versions up to 6.1.0 and was reported by researcher David Brown; the manufacturer published the patch in version 6.1.1 on May 20.

The technical problem lies in a "temporary access" functionality designed for remote technical support: an AJAX route that was to authorize applications is based only on a nonce exposed in the front JavaScript. Since this check can be played from any client, an attacker can send a request designed to create a user with an administrator role, generate a "magic" login URL and receive it on a remote server. When visiting that URL the attacker automatically enters with administrative privileges without password or additional verification.

Security Alert: WP Maps Pro allows you to create administrator accounts without authentication (CVE-2026-8732)
Image generated with IA.

This vector is dangerous because of its simplicity and the impact it has: a web administrator created ex nihilo allows to insert persistent back doors, upload web shells, install malicious plugins, steal data, modify content or pivote to other connected systems. Defiant (Wordfence) has documented that thousands of exploitative attempts have already been blocked in a few hours, a clear sign that attackers are actively scanning and exploiting sites.

If you manage a WordPress site, the first and most urgent action is to verify the version of the WP Maps Pro plugin and update it immediately at 6.1.1 or more. If you cannot apply the patch safely in the immediate window, disable and remove the plugin until you can install the corrected version: the risk of leaving the plugin active is very high. You can read the technical analysis and the timing of the incident in the Wordfence public report in this link: Wordfence: vulnerability analysis in WP Maps Pro.

In addition to updating or disabling the plugin, do a quick forensic search in your installation. Check the list of users looking for recently created accounts or suspicious mail addresses (for example, any support appearance @ flippercode.com), inspect the wp _ usermeta table for unusual keys that may contain "magic" login links, and check the web access logs for POST requests to the AJAX plugin endpoints. If you detect unauthorized administrative accounts, cut them and check directories for newly uploaded or modified files that can be backdoors.

It is not enough to remove any malicious user: it is committed if the vulnerability was exploited. Restores from a clean pre-intrusion backup if available, changes all critical administrators and users passwords, broken API keys and integrated service credentials, and updates WordPress keys and salts. It also runs a scan with security tools (e.g. Wordfence or Sucuri) to detect web shells and persistent modifications.

For teams that manage multiple sites or cannot stop services, implement temporary mitigation: block the AJAX plugin routes at the WAF level, restrict access to the IP plugin directory (if applicable) and monitor user creation attempts with automatic alerts. Please note that these measures are palliative and none of them replace the plugin update.

Security Alert: WP Maps Pro allows you to create administrator accounts without authentication (CVE-2026-8732)
Image generated with IA.

Beyond the immediate response, this incident illustrates a recurring security lesson: the authorisation checks must be carried out on the server, not in public JavaScript. Remote support functions should use signed tokens on the server, more robust source checks, and record and limit the use of temporary access to avoid abuse. Plugins must design the remote support with the principle of minimum privilege and with short and verifiable expiry.

If you want to check the CVE public record for more technical details and status, the NVD database contains the corresponding entry: NVD - CVE-2026-8732. Staying informed and acting quickly remains the best defense: patching, hearing and monitoring.

Finally, he recalls that attackers are going to re-use similar techniques in other plugins that expose support logic or administration from the front; it adopts regular updating policies, file integrity tests and a proven backup strategy to reduce the impact of future intrusions.

Coverage

Related

More news on the same subject.