By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Cybersecurity Beat
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
Reading: WordPress Plugin Flaw Lets Attackers Take Over Sites via Admin Creation
  • AI
  • Android
  • Authentication
  • Breaches
  • CASB
  • Compliance
  • Cryptography
  • Cyberinsurance
  • EDR
  • IAM
  • Malware
  • Phishing
  • Quantum
  • Ransomware
  • SecOps
  • SIEM
  • SOC
  • Threat Intelligence
  • Vulnerabilities
  • Zero Trust
Cybersecurity BeatCybersecurity Beat
Font ResizerAa
Search
  • News & Alerts
  • Articles
  • Spotlight
  • Features
  • Resources
Follow US
  • About CSB
  • Services
  • Contact
  • Privacy
  • Legal
©2026 CybersecurityBeat. All Rights Reserved.
News & Alerts

WordPress Plugin Flaw Lets Attackers Take Over Sites via Admin Creation

Attackers are exploiting a privilege escalation bug in the WP Maps Pro WordPress plugin to create unauthorized administrator accounts on vulnerable websites.

CSBadmin
Last updated: June 1, 2026 11:05 am
CSBadmin
2 Min Read
Share
SHARE

How the Exploit Works

A critical security vulnerability has been discovered in WP Maps Pro, a WordPress plugin with over 15,000 sales. The flaw allows unauthenticated attackers to create administrator accounts on affected websites, giving them full control. The issue stems from a “temporary access” feature intended to let support staff log into customer sites for troubleshooting.

Contents
How the Exploit WorksImpact and Remediation

Attackers can invoke a specific function without proper authentication checks. A nonce used to protect the function is publicly embedded on every frontend page of the site, making it useless as a security barrier. This allows the attacker to create a new user with administrator privileges and receive a magic login link that fully authenticates them.

Impact and Remediation

All versions of WP Maps Pro up to and including version 6.1.0 are vulnerable. The plugin developer has released version 6.1.1 to address the flaw. Site owners using this plugin should update immediately to prevent takeover attempts.

Active exploitation has been observed in the wild, according to security researchers. The vulnerability carries a severity score of 9.8 out of 10. Security researcher David Brown discovered and reported the issue. For administrators, checking for unknown administrator accounts and reviewing recent user creation activity is recommended to detect potential compromises.

Source: The Hacker News

CSBadmin

The latest in cybersecurity news and updates.

TAGGED:Account TakeoverWP Maps Pro
Share This Article
Facebook Print
ByCSBadmin
Follow:
The latest in cybersecurity news and updates.
Previous Article Microsoft 365 MFA Setup Disruption Blocks User Enrollment and Portal Access
Next Article Container Misconfigurations Open Pathway to Host Takeovers

Trending

Iran-linked actors use AI to accelerate malware and phishing operations
July 20, 2026
Critical 7-zip vulnerability allows code execution via XZ archives
July 20, 2026
Hugging face says autonomous AI agent breached its infrastructure
July 20, 2026
Critical Nginx bug CVE-2026-42533 allows remote code execution via HTTP
July 20, 2026
Russian intelligence hacked IP cameras to spy on NATO military logistics
July 20, 2026

Related Stories

CSBadmin

Palo Alto Networks Patches Actively Exploited PAN OS Flaw

CSBadmin

New LONGLEASH Malware Expands Chinese APT’s Relay Network

CSBadmin

Salt Typhoon Expands Global Router Attacks, Targeting Critical Sectors

CSBadmin

Supply Chain Attack Backdoors ShapedPlugin WordPress Pro Plugins

csb-sized
  • About CSB
  • Services
  • Contact
  • Privacy
  • Legal

© 2026 Cybersecurity Beat. All rights reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?