The images in this article were generated with artificial intelligence. How we publish
A critical failure in the premium WP Maps Pro plugin for WordPress has started to be exploited in nature and allows attackers to create administrator accounts without authentication, which turns sites with old versions of the plugin into high value targets. Vulnerability, recorded as CVE-2026-8732, affects versions up to 6.1.0 and was reported by researcher David Brown; the manufacturer published the patch in version 6.1.1 on May 20.
The technical problem lies in a "temporary access" functionality designed for remote technical support: an AJAX route that was to authorize applications is based only on a nonce exposed in the front JavaScript. Since this check can be played from any client, an attacker can send a request designed to create a user with an administrator role, generate a "magic" login URL and receive it on a remote server. When visiting that URL the attacker automatically enters with administrative privileges without password or additional verification.

This vector is dangerous because of its simplicity and the impact it has: a web administrator created ex nihilo allows to insert persistent back doors, upload web shells, install malicious plugins, steal data, modify content or pivote to other connected systems. Defiant (Wordfence) has documented that thousands of exploitative attempts have already been blocked in a few hours, a clear sign that attackers are actively scanning and exploiting sites.
If you manage a WordPress site, the first and most urgent action is to verify the version of the WP Maps Pro plugin and update it immediately at 6.1.1 or more. If you cannot apply the patch safely in the immediate window, disable and remove the plugin until you can install the corrected version: the risk of leaving the plugin active is very high. You can read the technical analysis and the timing of the incident in the Wordfence public report in this link: Wordfence: vulnerability analysis in WP Maps Pro.
In addition to updating or disabling the plugin, do a quick forensic search in your installation. Check the list of users looking for recently created accounts or suspicious mail addresses (for example, any support appearance @ flippercode.com), inspect the wp _ usermeta table for unusual keys that may contain "magic" login links, and check the web access logs for POST requests to the AJAX plugin endpoints. If you detect unauthorized administrative accounts, cut them and check directories for newly uploaded or modified files that can be backdoors.
It is not enough to remove any malicious user: it is committed if the vulnerability was exploited. Restores from a clean pre-intrusion backup if available, changes all critical administrators and users passwords, broken API keys and integrated service credentials, and updates WordPress keys and salts. It also runs a scan with security tools (e.g. Wordfence or Sucuri) to detect web shells and persistent modifications.
For teams that manage multiple sites or cannot stop services, implement temporary mitigation: block the AJAX plugin routes at the WAF level, restrict access to the IP plugin directory (if applicable) and monitor user creation attempts with automatic alerts. Please note that these measures are palliative and none of them replace the plugin update.

Beyond the immediate response, this incident illustrates a recurring security lesson: the authorisation checks must be carried out on the server, not in public JavaScript. Remote support functions should use signed tokens on the server, more robust source checks, and record and limit the use of temporary access to avoid abuse. Plugins must design the remote support with the principle of minimum privilege and with short and verifiable expiry.
If you want to check the CVE public record for more technical details and status, the NVD database contains the corresponding entry: NVD - CVE-2026-8732. Staying informed and acting quickly remains the best defense: patching, hearing and monitoring.
Finally, he recalls that attackers are going to re-use similar techniques in other plugins that expose support logic or administration from the front; it adopts regular updating policies, file integrity tests and a proven backup strategy to reduce the impact of future intrusions.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...