Junglewise Threat Intelligence

CVE-2026-8732: WP Maps Pro privilege escalation via administrator account creation

CVE-2026-8732 · Severity: critical · CVSS 9.8 · Published 2026-05-29

Executive brief

WP Maps Pro is a popular WordPress plugin used to display interactive maps on websites. A critical security flaw allows anyone on the internet to automatically create a new administrator account on a site using this plugin. This grants an attacker full control over the website, allowing them to steal data, modify content, or lock out legitimate owners.

Technical details

The WP Maps Pro plugin for WordPress is vulnerable to privilege escalation due to an insecurely implemented AJAX action, 'wpgmp_temp_access_ajax'. This action is registered with 'wp_ajax_nopriv_', making it accessible to unauthenticated users. While it uses a nonce check for protection, the required nonce is publicly exposed on every frontend page via 'wp_localize_script'. An attacker can use this nonce to invoke the 'wpgmp_temp_access_support' handler with the 'check_temp' parameter set to false. This triggers 'wp_insert_user()' to create a new administrator account and returns a magic login URL that authenticates the attacker via 'wp_set_auth_cookie()', leading to a complete site takeover.

Affected products

  • WP Maps Pro WP Maps Pro Up to, and including, 6.1.0

Timeline

  • 2026-05-29: disclosed
  • 2026-05-29: advisory

References

Related threats