logo

WP Maps Pro Vulnerability Exposed 15,000 WordPress Sites to Site Takeover

ID: e37889ec-ee81-508c-9ca0-9fba93f5057b

STIX ID: report--e37889ec-ee81-508c-9ca0-9fba93f5057b

Feed Name: The Cyber Express

Threat Score
78/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: Ashish Khaitan

...
...

The report details a critical unauthenticated privilege-escalation vulnerability in the WP Maps Pro WordPress plugin (<= 6.1.0) that let attackers create administrator accounts via a vulnerable AJAX action (exposed nonce and wp_ajax_nopriv_). Successful exploitation enabled full site takeover (install plugins, backdoors, webshells, data theft). Wordfence validated the exploit, deployed mitigation rules, and the vendor released a fix in version 6.1.1 that restricts the endpoint to administrators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.