logo

Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts

ID: 6a783232-8bc4-5f84-ae5f-2f2863987e18

STIX ID: report--6a783232-8bc4-5f84-ae5f-2f2863987e18

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-06-01

Date Updated: 2026-06-01

Author: [email protected] (The Hacker News)

...
...

A critical privilege-escalation vulnerability (CVE-2026-8732, CVSS 9.8) in the WP Maps Pro WordPress plugin allows unauthenticated attackers to create administrator accounts and achieve full site takeover; the plugin was patched in version 6.1.1, but Wordfence reported active exploitation and blocked 2,858 attacks in 24 hours, so immediate patching is advised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.