CVE-2026-8732 – Critical Unauthenticated Admin Takeover in WP Maps Pro
Key Takeaways
- Critical vulnerability (CVE-2026-8732) in WP Maps Pro lets unauthenticated attackers create a WordPress admin account.
- Active exploitation observed; 2,858 attacks blocked in a single 24‑hour window.
- Affected versions: ≤ 6.1.0; a patch is available in 6.1.1.
- Immediate actions: apply the patch, audit for rogue admin accounts, and block the vulnerable AJAX endpoint.
Overview
On June 1 2026, security researchers disclosed CVE‑2026‑8732, a Critical privilege‑escalation flaw in the popular WordPress plugin WP Maps Pro. The vulnerability enables an unauthenticated remote attacker to create a new WordPress administrator account without providing any credentials. Exploits have been seen in the wild, with thousands of attempts blocked by web‑application firewalls within a single day.
For live threat‑activity trends, exploit counts, and a full timeline, see the VulnSocial CVE page.
Technical Details
The flaw resides in the AJAX handler wpgmp_temp_access_ajax (the “temporary access” endpoint). The plugin relies on a nonce (fc-call-nonce) to restrict access, but the nonce verification can be bypassed by sending the request with the parameter check_temp=false. When the bypass succeeds, the handler:
- Creates a new WordPress user with the
administratorrole. - Generates a “magic login” URL that, when visited, authenticates the attacker as the newly created admin.
The vulnerable request looks like:
POST /wp-admin/admin-ajax.php?action=wpgmp_temp_access_ajax&check_temp=false HTTP/1.1
Host: <target>
No authentication or valid nonce is required. The response includes a URL similar to:
https://<target>/wp-login.php?action=rp&key=<random>&login=admin
Visiting this URL grants full admin privileges.
Key technical observations:
- The nonce is not validated when
check_tempis false, effectively disabling the primary security check. - The endpoint is publicly reachable to any unauthenticated visitor.
- The plugin does not log the admin‑creation event, making detection difficult without additional monitoring.
Severity & Impact
| Metric | Value |
|---|---|
| CVE ID | CVE-2026-8732 |
| Severity | Critical |
| CVSS | CVSS 9.8 (NIST) |
| Impact | Full site takeover – attacker obtains administrator rights, can install plugins, modify content, exfiltrate data, and pivot to other systems. |
The Critical rating reflects the complete loss of confidentiality, integrity, and availability of the compromised WordPress site. An attacker can install malicious code, deface the site, exfiltrate data, or use the site as part of a larger botnet.
Affected Products
- WP Maps Pro versions ≤ 6.1.0 (all releases prior to the 6.1.1 patch).
- The plugin is distributed via the official WordPress plugin repository and commercial marketplaces (e.g., Envato).
For the exhaustive list of affected versions and distribution channels, see the CVE page.
Actionable Insights – What to Do Now
- Deploy the official patch: update to WP Maps Pro 6.1.1 or later via the WordPress admin dashboard or WP‑CLI.
- Audit existing user accounts:
- Search for admin users created after May 30 2026 that you did not create.
- Reset passwords for any suspicious accounts and enable two‑factor authentication.
- Block the vulnerable endpoint at the web‑application firewall (WAF) level:
- Rule to block or require authentication for
admin-ajax.php?action=wpgmp_temp_access_ajax.
- Rule to block or require authentication for
- Monitor logs for the
wpgmp_temp_access_ajaxaction and for the creation of admin accounts (user_registerhook) in real time. - Rotate all privileged credentials (WordPress admin passwords, API keys) in case an attacker already gained access.
- Leverage threat‑intel feeds (e.g., VulnSocial) to watch for new exploitation attempts targeting your WordPress instances.
Remediation & Mitigation (Step‑by‑Step)
- Update the plugin
wp plugin update wp-maps-pro --version=6.1.1 - Verify the update – confirm the plugin version in the admin UI or via:
wp plugin status wp-maps-pro - Run a user audit – list all administrators:
wp user list --role=administrator --fields=ID,user_login,display_name,user_email - Remove unknown admins – for each suspicious user:
wp user delete <user_id> --reassign=1 - Add a WAF rule (example for ModSecurity):
SecRule REQUEST_URI "@contains wpgmp_temp_access_ajax" "id:1000001,phase:2,deny,status:403,msg:'Block WP Maps Pro temp access exploit'" - Enable logging of admin‑creation events (add to
functions.phpif needed):add_action('user_register', function($user_id) { error_log('New user created: ' . $user_id); });
Summary
CVE‑2026‑8732 is a Critical (CVSS 9.8) unauthenticated privilege‑escalation flaw in WP Maps Pro that lets attackers create full WordPress admin accounts via a nonce bypass. Active exploitation has been confirmed, with thousands of attempts blocked in a single day. The vulnerability affects all versions ≤ 6.1.0; a patch is available in 6.1.1. Immediate remediation, user‑account audit, and endpoint blocking are essential to prevent site takeover.
References
#CVE #CVE20268732 #Critical #WPMapsPro #WordPress #Exploit #ActiveExploitation #Remediation
