Executive brief
A critical security flaw in the WP MAPS PRO plugin for WordPress allows unauthorized individuals to gain full control over a website. By exploiting a weakness in how the plugin handles map scripts, an attacker can automatically create a new administrator account and receive a direct login link. This bypasses all security measures, leading to a complete takeover of the site, its data, and its operations.
Technical details
The WP MAPS PRO (formerly Advanced Google Maps) plugin for WordPress fails to implement proper authorization checks on a registered AJAX action. An unauthenticated attacker can capture a security nonce that is publicly exposed on any frontend page where a map is displayed. By submitting this nonce to the vulnerable AJAX endpoint, the plugin unconditionally creates a new user with administrator privileges and returns a 'magic-login' URL. This allows for complete site compromise without any prior credentials. The issue is resolved in version 6.1.1.
Affected products
- WP MAPS PRO WP MAPS PRO (Advanced Google Maps) < 6.1.1
Timeline
- 2026-05-25: disclosed: Publicly published by WPScan
- 2026-06-15: advisory: NVD publication date