


Perceptive Security
SOC/SIEM Consultancy

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This …
Published:
28 mei 2026 om 22:00:00
Alert date:
29 mei 2026 om 08:00:33
Source:
nvd.nist.gov
Web Technologies
The WP Maps Pro WordPress plugin contains a critical privilege escalation vulnerability in versions up to 6.1.0. The vulnerability allows unauthenticated attackers to create administrator accounts through an improperly secured AJAX action. The wpgmp_temp_access_ajax action is protected only by a publicly accessible nonce, making the security check ineffective. Attackers can exploit this to invoke wpgmp_temp_access_support with check_temp=false, automatically creating a new administrator user and receiving a magic login URL for complete site takeover.
Technical details
Mitigation steps:
Affected products:
WP Maps Pro WordPress Plugin
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-8732
https://codecanyon.net/item/advanced-google-maps-plugin-for-wordpress/5211638
https://www.wordfence.com/threat-intel/vulnerabilities/id/65988550-d39d-40be-8d25-647e7237062d?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
