WP Maps Pro unauthenticated admin-account-creation flaw (CVE-2026-8732)
Vulnerability
Summary
Hide ▲
Show ▼
WP Maps Pro versions 6.1.0 and older contain CVE-2026-8732, an unauthenticated flaw that can create rogue administrator accounts and lead to full WordPress site takeover. Defiant observed active targeting and blocked more than 3,600 attempts in 24 hours. A fix is available in WP Maps Pro 6.1.1, and site owners should update immediately.
Related Happenings
Service Finder WordPress theme active auth bypass exploitation wave (CVE-2025-5947)
Exploitation Wave
First: 08.10.2025 18:57
Last: 08.10.2025 18:57
Sources 1
About this happening:
**CVE-2025-5947** is being exploited at scale against the **Service Finder WordPress theme**, with attackers using an authentication bypass to log in as administrators and take ov...
Service Finder WordPress theme active auth bypass exploitation wave (CVE-2025-5947)
Exploitation WaveAbout this happening: **CVE-2025-5947** is being exploited at scale against the **Service Finder WordPress theme**, with attackers using an authentication bypass to log in as administrators and take ov...
Timeline
-
31.05.2026 17:06 2 articles · 1h ago
Defiant blocks more than 3,600 WP Maps Pro exploitation attempts
Exploitation ObservedDefiant observed threat actors targeting WordPress websites running WP Maps Pro 6.1.0 and older and blocked more than 3,600 exploitation attempts in the 24 hours before May 31, 2026.
Show sources
- WP Maps Pro bug exploited to create admin accounts on WordPress sites — www.bleepingcomputer.com — 31.05.2026 17:06
- WP Maps Pro bug exploited to create admin accounts on WordPress sites — www.bleepingcomputer.com — 31.05.2026 17:06
-
20.05.2026 03:00 1 articles · 11d ago
WP Maps Pro 6.1.1 fixes CVE-2026-8732
Mitigation Patch UpdateWP Maps Pro 6.1.1 was released on May 20 with a fix for CVE-2026-8732, closing the unauthenticated admin-account-creation flaw in WP Maps Pro versions 6.1.0 and older.
Show sources
- WP Maps Pro bug exploited to create admin accounts on WordPress sites — www.bleepingcomputer.com — 31.05.2026 17:06
-
16.05.2026 03:00 1 articles · 15d ago
Wordfence validates the WP Maps Pro exploit and notifies the vendor
Technical Analysis UpdateAfter validating the exploit, Wordfence notified the WP Maps Pro vendor on May 16 about CVE-2026-8732, a critical flaw in versions 6.1.0 and older that lets unauthenticated users create administrator accounts.
Show sources
- WP Maps Pro bug exploited to create admin accounts on WordPress sites — www.bleepingcomputer.com — 31.05.2026 17:06
-
24.03.2026 02:00 1 articles · 2mo ago
David Brown reports CVE-2026-8732 in WP Maps Pro to Wordfence
Initial DisclosureSecurity researcher David Brown reported CVE-2026-8732 in the WP Maps Pro WordPress plugin to Wordfence on March 24 after identifying an unauthenticated path that could create administrator accounts on WordPress sites.
Show sources
- WP Maps Pro bug exploited to create admin accounts on WordPress sites — www.bleepingcomputer.com — 31.05.2026 17:06