Menu

Post image 1
Post image 2
1 / 2
0

Critical WordPress Plugin Flaw Exposes 15,000 Sites to Instant Admin Takeover

WebProNews·Emma Rogers·3 months ago
#npFDmxPT
Reading 0:00
15s threshold

WordPress site administrators woke up to fresh alerts last week. A popular premium mapping plugin carried a critical vulnerability that let anyone create a full administrator account without credentials or prior access. The flaw, now tracked as CVE-2026-8732 , earned a 9.8 CVSS score. Exploitation surged immediately after disclosure. WP Maps Pro sells on the Envato Market. More than 15,000 copies have moved. Businesses rely on it for interactive Google Maps embeds, store locators, and location directories. The plugin supports OpenStreetMap too. Its reach made the bug especially dangerous. Security researcher David Brown found the issue. He reported it to Wordfence on March 24, 2026. Validation took time. The vendor, WePlugins, received formal notice on May 16. A patch arrived four days later in version 6.1.1, released May 20. By then attackers had already begun scanning. The vulnerability sits inside a feature called Temporary Access.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More