logo

CVE-2026-8935: WP Maps Pro Unauthenticated Admin Account Creation (CVSS 9.8)

ID: 0f5ca385-0e88-5b72-a0fa-93d6c86a3841

STIX ID: report--0f5ca385-0e88-5b72-a0fa-93d6c86a3841

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-06-15

Date Updated: 2026-06-16

...
...

A critical-severity vulnerability (CVE-2026-8935, CVSS 9.8) in WP Maps Pro (< 6.1.1) allows any unauthenticated visitor to extract a public nonce from a page that loads the plugin, call a vulnerable admin-ajax.php action which unconditionally creates an administrator account, and receive a magic login URL to gain immediate full administrator access; site owners should update to 6.1.1, audit users and logs, rotate credentials, and check for unauthorized changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.