Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts
A critical security flaw (CVE-2026-8732) in the WP Maps Pro WordPress plugin has been actively exploited to create administrator accounts on vulnerable websites. The vulnerability stems from a flaw in the plugin's temporary access feature, allowing unauthenticated attackers to gain full control. Plugin maintainers have released a patch, but proactive updates are crucial to mitigate the ongoing threat.
The WP Maps Pro plugin, widely used for embedding maps on WordPress sites, is currently facing a significant security risk. Threat actors are leveraging a critical vulnerability (CVE-2026-8732) to gain unauthorized administrative access to websites using the plugin. This flaw allows attackers to bypass standard security measures and create administrator accounts without needing to compromise passwords or other credentials. The vulnerability lies within the plugin's temporary access feature, which was designed for support staff to troubleshoot issues, but was improperly secured.
