WP Maps Pro bug exploited to create admin accounts on WordPress sites
A critical vulnerability (CVE-2026-8732) in the WP Maps Pro WordPress plugin has been exploited by threat actors to create administrator accounts on affected websites. The flaw stems from an insecure AJAX endpoint that allows unauthorized access and account creation, posing a significant risk to website security. Security researchers and the plugin vendor have released a patch, but website administrators are urged to update immediately to mitigate the ongoing threat.
Hackers are actively targeting WordPress websites utilizing vulnerable versions of the WP Maps Pro plugin. The vulnerability, CVE-2026-8732, allows attackers to bypass authentication and create administrator accounts without needing a password. This was facilitated by an insecure AJAX endpoint designed for vendor support, which was accessible to anyone, relying solely on a weak JavaScript nonce check. Exploitation involves crafting a specific request that triggers the creation of a new WordPress user with administrator privileges, generating a login URL, and automatically logging the attacker into the account. This level of access allows for extensive malicious activity, including backdoor installation, data theft, and website takeover.