By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Threatwire
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
      • Drinkware
      • T-Shirts
    • Cart
Reading: WordPress Plugin Flaw Lets Attackers Take Over Sites via Admin Creation
0

No products in the cart.

  • AI
  • Android
  • Authentication
  • Breaches
  • CASB
  • Compliance
  • Cryptography
  • Cyberinsurance
  • EDR
  • IAM
  • Malware
  • Phishing
  • Quantum
  • Ransomware
  • SecOps
  • SIEM
  • SOC
  • Threat Intelligence
  • Vulnerabilities
  • Zero Trust
ThreatwireThreatwire
Font ResizerAa
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
  • Newsletter
  • Shop
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
    • Cart
Follow US
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal
©2026 CybersecurityBeat. All Rights Reserved.
News & Alerts

WordPress Plugin Flaw Lets Attackers Take Over Sites via Admin Creation

Attackers are exploiting a privilege escalation bug in the WP Maps Pro WordPress plugin to create unauthorized administrator accounts on vulnerable websites.

CSBadmin
Last updated: June 1, 2026 11:05 am
CSBadmin
2 Min Read
Share
SHARE

How the Exploit Works

A critical security vulnerability has been discovered in WP Maps Pro, a WordPress plugin with over 15,000 sales. The flaw allows unauthenticated attackers to create administrator accounts on affected websites, giving them full control. The issue stems from a “temporary access” feature intended to let support staff log into customer sites for troubleshooting.

Contents
How the Exploit WorksImpact and Remediation

Attackers can invoke a specific function without proper authentication checks. A nonce used to protect the function is publicly embedded on every frontend page of the site, making it useless as a security barrier. This allows the attacker to create a new user with administrator privileges and receive a magic login link that fully authenticates them.

Impact and Remediation

All versions of WP Maps Pro up to and including version 6.1.0 are vulnerable. The plugin developer has released version 6.1.1 to address the flaw. Site owners using this plugin should update immediately to prevent takeover attempts.

Active exploitation has been observed in the wild, according to security researchers. The vulnerability carries a severity score of 9.8 out of 10. Security researcher David Brown discovered and reported the issue. For administrators, checking for unknown administrator accounts and reviewing recent user creation activity is recommended to detect potential compromises.

Source: The Hacker News

CSBadmin

The latest in cybersecurity news and updates.

TAGGED:Account TakeoverWP Maps Pro
Share This Article
Facebook Print
ByCSBadmin
Follow:
The latest in cybersecurity news and updates.
Previous Article Microsoft 365 MFA Setup Disruption Blocks User Enrollment and Portal Access
Next Article Container Misconfigurations Open Pathway to Host Takeovers

Trending

StreamRat trojan rides fake TV apps to take over Android devices
September 3, 2026
Signed node.exe is latest cover for malware delivery, Symantec finds
September 3, 2026
Russian man extradited over Excel malware sent to 80,000 freelancers
September 3, 2026
Fake tax and shipping lures push RMM installs across 46 countries
September 3, 2026
Poisoned Git configs make AI coding agents run attacker commands
September 3, 2026

Related Stories

CSBadmin

Law Enforcement Dismantles AI Driven Phishing Network Tied to 3.8 Million Stolen Credit Cards

CSBadmin

Massive Scans Target Cisco ASA Devices, Raising Fears of Imminent Exploit

CSBadmin

Poisoned Tool Descriptions Can Hijack AI Agents to Exfiltrate Data

CSBadmin

Opera GX Browser Mod Exploit Steals User Data via Silent CSS Injection

logo-twfull
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal

© 2026 Threatwire / Cybersecurity Beat. All rights reserved.