Multiple outlets report that attackers are actively exploiting a critical vulnerability in the commercial WordPress plugin WP Maps Pro to gain administrative access on compromised sites. The flaw, identified as CVE-2026-8732 (reported with a CVSS score of 9.8 by one outlet), allows unauthenticated attackers to create rogue administrator accounts without requiring login or other authentication. Once the accounts are created, an attacker can take over the WordPress installation.
Reports indicate that the plugin is widely used among WordPress sites, with one outlet noting more than 15,000 sales on the Envato Market. Security researchers and coverage describe the vulnerability as enabling attackers to register admin-level users on installations running vulnerable versions of the plugin. One source also says attack attempts were frequent, with about 3,600 attempts recorded in a single day.
The coverage also notes that a patch is being rolled out, implying remediation steps for sites running affected versions of WP Maps Pro. The overall reporting is consistent that the vulnerability is being used in the wild to create unauthorized administrator accounts.