#9
The Hacker News
general
June 01, 2026 at 08:45 UTC
Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts
By [email protected] (The Hacker News)
AI Summary
CVE-2026-8732, a critical unauthenticated privilege escalation flaw in the WP Maps Pro WordPress plugin (with over 15,000 Envato Market sales), is being actively exploited to create rogue administrator accounts on vulnerable sites. The plugin allows embedding Google Maps and OpenStreetMap features, making it a widely deployed target. WordPress site owners using WP Maps Pro should update immediately and audit admin user lists for unauthorized accounts.
Relevance score: 76.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →