WordPress site administrators woke up to fresh alerts last week. A popular premium mapping plugin carried a critical vulnerability that let anyone create a full administrator account without credentials or prior access. The flaw, now tracked as CVE-2026-8732 , earned a 9.8 CVSS score. Exploitation surged immediately after disclosure. WP Maps Pro sells on the Envato Market. More than 15,000 copies have moved. Businesses rely on it for interactive Google Maps embeds, store locators, and location directories. The plugin supports OpenStreetMap too. Its reach made the bug especially dangerous. Security researcher David Brown found the issue. He reported it to Wordfence on March 24, 2026. Validation took time. The vendor, WePlugins, received formal notice on May 16. A patch arrived four days later in version 6.1.1, released May 20. By then attackers had already begun scanning. The vulnerability sits inside a feature called Temporary Access.…