The active exploitation of the WP Maps Pro vulnerability is another reminder that WordPress plugins can become full site-takeover paths when access controls are weak. The flaw, tracked as CVE-2026-8732, affects WP Maps Pro versions 6.1.0 and earlier and allows unauthenticated attackers to create rogue administrator accounts on vulnerable WordPress sites.
This is especially serious because admin access to WordPress is not a small compromise. Attackers can change site content, inject malicious JavaScript, redirect visitors to phishing pages, install backdoors, steal data, upload web shells, create new users, and abuse the trusted domain for malware delivery. In other words, one vulnerable plugin can turn a normal website into someone else’s criminal infrastructure, because apparently even map plugins now need a security clearance.
The issue reportedly comes from a “temporary access” feature intended for vendor support, which was not properly protected. Attackers can abuse it to generate administrator access without valid credentials. That should concern every website owner using third-party plugins, especially premium or niche plugins that may not be monitored as closely as core WordPress updates.
Site administrators should immediately update WP Maps Pro to the fixed version, review all administrator accounts, remove unknown users, check for suspicious plugins or themes, inspect recent file changes, and review server logs for abuse of wpgmp_temp_access_ajax. If compromise is suspected, reset admin passwords, rotate database and hosting credentials, and scan the site for injected scripts or web shells.
The broader lesson is simple: WordPress security is plugin security. Keeping WordPress core updated is not enough if third-party plugins can create admin accounts without authentication. Plugin inventory, timely updates, least-privilege admin access, WAF protection, backups, file-integrity monitoring, and regular account reviews should be basic hygiene for every public-facing WordPress site.
Hackers are targeting WordPress websites running a vulnerable version of the WP Maps Pro plugin, which allows creating rogue administrator accounts without authentication. [...]
Source: WP Maps Pro bug exploited to create admin accounts on WordPress sites via Bleeping Computer — published 31 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.