WP Maps Pro bug exploited to create admin accounts on WordPress sites
WordPress websites using a vulnerable version of the WP Maps Pro plugin—which permits the creation of rogue administrator accounts without authentication—are the target of hackers.
The vulnerability affects WP Maps Pro versions 6.1.0 and earlier and is listed as CVE-2026-8732. It has a critical severity level. David Brown, a security researcher, found it and reported it.
A premium WordPress plugin called WP Maps Pro is used to create interactive, editable maps and store locators. Several map suppliers, including OpenStreetMap and Google Maps, are supported.
With over 15,800 sales on the Envato Market, the plugin is commonly utilized by companies, real estate websites, travel websites, directories, and organizations that require to display several locations on a map.
A "tempora...

