WordPress Plugin Security Update Advisory (CVE-2026-8732)

WordPress Plugin Security Update Advisory (CVE-2026-8732)

Overview


A security update has been issued for a vulnerability in the WordPress plugin WP Maps Pro. the vulnerability is an unauthenticated privilege escalation vulnerability (CVE-2026-8732), which can be exploited through the wpgmptempaccess_ajax AJAX Action (a feature that allows web applications to handle asynchronous requests) related to the way threat actors create administrator accounts.

Affected by


  • WP Maps Pro version 6.1.0 and earlier.

Workaround


  • the vulnerability has been patched in the latest update.
  • You should update to WP Maps Pro version 6.1.1 or later.

Notes


  • you should follow the instructions on the reference site to update to the latest version of the Vulnerability Patch.