Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The Real AI Disruption Isn’t the Technology. It’s the Company.

    September 14, 2026

    New York Seizes a Dozen Celebrity Deepfake Websites

    September 14, 2026

    The AI industry has taken a doomer turn. What now?

    September 14, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Real AI Disruption Isn’t the Technology. It’s the Company.
    • New York Seizes a Dozen Celebrity Deepfake Websites
    • The AI industry has taken a doomer turn. What now?
    • Countries Seek to Curb Social Media Addiction for Kids.
    • Google’s Genome Atlas Predicts the Effect of Every Possible DNA Mutation
    • AI Leaders Are Calling for a Slowdown. Trump’s Team Says It’s on Them
    • The Download: AI’s real extinction threat and age-reversal tech for eyes
    • Sexually Explicit Deepfake Sites Target 100-Plus Politicians in Europe
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites
    Cybersecurity

    WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites

    kirklandc008@gmail.comBy kirklandc008@gmail.comJune 1, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Worries About AI’s Risks to Humanity Loom Over the Trial Pitting Musk Against OpenAI’s Leaders
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors are exploiting a critical-severity vulnerability in the WP Maps Pro WordPress plugin to take over websites, Defiant warns.

    WP Maps Pro allows site administrators to embed Google Maps in their installations, customizable with advanced location, markers, and categories.

    The exploited vulnerability, tracked as CVE-2026-8732 (CVSS score of 9.8), allows unauthenticated threat actors to create new administrative accounts and take over vulnerable sites.

    WP Maps Pro has been designed to support tooling, which exposes a temporary access capability used by the vendor to log in to customer sites as part of troubleshooting operations.

    According to Defiant, the security defect exists in a callback AJAX function used to handle the temporary access generation, which is protected only by a nonce check.

    The nonce, it explains, is embedded in every frontend page and exposed to any unauthenticated user, which makes the nonce check ineffective.

    Advertisement. Scroll to continue reading.

    Furthermore, the plugin does not include capability checks, thus allowing unauthenticated attackers to invoke the AJAX action with a check_temp parameter set to false and create a new WordPress user with the role of administrator.

    The user is generated with a random username and with a hardcoded email address. Additionally, the function generates a magic login URL and returns it to the attacker, which can use it to authenticate without a password or additional verification.

    “As a result, an attacker gains full administrator-level control over the site and can install malicious plugins, modify themes, inject backdoors, exfiltrate data, or deploy web shells for persistent access,” Defiant explains.

    The vulnerability was addressed in WP Maps Pro version 6.1.1, which adds a capability check to restrict access to authenticated administrators.

    Defiant says it has blocked over 1,700 attacks targeting the CVE-2026-8732 over the past 24 hours.

    Related: CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day

    Related: Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack

    Related: Ally WordPress Plugin Flaw Exposes Over 200,000 Websites to Attacks

    Related: Exploited ‘Post SMTP’ Plugin Flaw Exposes WordPress Sites to Takeover

    exploited Maps Pro sites vulnerability WordPress
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Sexually Explicit Deepfake Sites Target 100-Plus Politicians in Europe

    September 14, 2026

    Balaji Ingole Develops AI Tools for E-Commerce Sites

    August 23, 2026

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • The Real AI Disruption Isn’t the Technology. It’s the Company.
    • New York Seizes a Dozen Celebrity Deepfake Websites
    • The AI industry has taken a doomer turn. What now?
    • Countries Seek to Curb Social Media Addiction for Kids.
    • Google’s Genome Atlas Predicts the Effect of Every Possible DNA Mutation

    The Real AI Disruption Isn’t the Technology. It’s the Company.

    September 14, 2026

    New York Seizes a Dozen Celebrity Deepfake Websites

    September 14, 2026

    The AI industry has taken a doomer turn. What now?

    September 14, 2026

    Countries Seek to Curb Social Media Addiction for Kids.

    September 14, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.