Skip to content
June 1, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Vulnerability Report
  • Critical WP Maps Pro Vulnerability Actively Exploited in the Wild
  • Vulnerability Report

Critical WP Maps Pro Vulnerability Actively Exploited in the Wild

Ddos May 28, 2026 3 minutes read
0
WP Maps Pro vulnerability exploited in the wild
Add as a preferred
source on Google

Recently, a major security threat emerged within the WordPress ecosystem. Attackers are actively targeting a critical flaw known as the WP Maps Pro vulnerability. Specifically, this zero-day flaw allows unauthenticated users to gain full administrative control. Because the bug is actively exploited in the wild, website owners must patch their systems immediately. Wordfence researchers discovered the flaw through their bug bounty program. Consequently, the community is racing to secure vulnerable web platforms.

Inside the Rogue Account Creation Flaw

To begin with, the security flaw resides in the way the plugin handles technical support tools. The software provides a temporary access option to help vendor developers solve technical issues. However, the underlying code fails to verify the privileges of the user making the request. According to the official advisory, “This vulnerability makes it possible for unauthenticated attackers to create new administrator accounts on the affected sites, leading to complete site takeover.”

Furthermore, the plugin utilizes a specific callback function called wpgmp_temp_access_ajax_callback(). This endpoint lacks a capability check in the vulnerable versions. Although the system includes a nonce check, external visitors can easily obtain this token. Therefore, anyone can trigger the backend script to insert a rogue administrator user into the database.

Active Exploitation and Severe Impact

Once the rogue account is created, the attacker receives a secret login URL. When the malicious actor visits this link, the site fully authenticates them without a password. As a result, the attacker gains full control over the compromised website. They can install malicious plugins or exfiltrate private data fields.

Currently, threat groups are heavily weaponizing the WP Maps Pro vulnerability across the web. Defensive telemetry indicates that hackers are rapidly launching automated campaigns against vulnerable targets. For instance, the published report states that “Wordfence blocked 2,514 attacks targeting this vulnerability in the past 24 hours.”. These statistics show how fast attackers exploit newly disclosed vulnerabilities.

Mandatory Patching Actions

Upgrading the Plugin

Fortunately, the software vendor released a secure update to eliminate this threat vector. The provider fixed the issue by adding a robust capability check to the vulnerable endpoint. This check ensures that only logged-in administrators can access the support function. Consequently, the system blocks unauthenticated requests automatically.

Future Security Advice

Webmasters must upgrade to version 6.1.1 or higher immediately to secure their digital spaces. In addition, security teams should implement a web application firewall to detect automated exploitation patterns. Monitoring user creation logs also helps detect unauthorized account modifications early. Ultimately, maintaining up-to-date software remains the most effective defense against modern cyber threats.

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. Hackers Actively Exploiting 9.8 Critical RCE Flaw in Kali Forms WordPress Plugin
  2. Over 400,000 WordPress Sites at Risk as “Breeze” Plugin Zero-Day Is Exploited in the Wild
  3. 200K Sites at Risk: 9.8 CVSS RCE via Burst Statistics Auth Bypass Exploited in the Wild
Tags: administrator account creation flaw CVE-2026-8732 Wordfence wordpress security WP Maps Pro

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-48879CVSS 9.8
    Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue...
  • CVE-2026-48866CVSS 9.6
    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability...
  • CVE-2026-42682CVSS 9.1
    Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access...
  • CVE-2026-42680CVSS 9.8
    Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery...
  • CVE-2026-47413CVSS 9.6
    ## Summary **Type:** Privilege escalation / cross-tenant member injection. The `POST /workspaces/{workspace_id}/members`...
  • CVE-2026-47428CVSS 9.6
    ## Summary Vitest browser mode served `/__vitest_test__/` with the `otelCarrier` query parameter...
  • CVE-2026-7858CVSS 9.8
    A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic...
  • CVE-2026-48188CVSS 9.1
    An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer...
  • CVE-2026-10187CVSS 9.8
    A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue...
  • CVE-2018-25412CVSS 9.8
    Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity © All rights reserved.