


Perceptive Security
SOC/SIEM Consultancy

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This …
Published:
28 May 2026 at 22:00:00
Alert date:
29 May 2026 at 14:01:48
Source:
nvd.nist.gov
Web Technologies
The WP Maps Pro plugin for WordPress versions up to 6.1.0 contains a critical privilege escalation vulnerability that allows unauthenticated attackers to create administrator accounts and achieve complete site takeover. The vulnerability exists in the wpgmp_temp_access_ajax AJAX action which is improperly protected by a publicly exposed nonce value. Attackers can exploit the wpgmp_temp_access_support handler to create administrator users and obtain magic login URLs for authentication bypass. This results in full administrative access to affected WordPress sites.
Technical details
Mitigation steps:
Affected products:
WP Maps Pro WordPress Plugin
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-8732
https://codecanyon.net/item/advanced-google-maps-plugin-for-wordpress/5211638
https://www.wordfence.com/threat-intel/vulnerabilities/id/65988550-d39d-40be-8d25-647e7237062d?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
