WordPress Plugin Security Update Advisory (CVE-2026-8732)
Overview
A security update has been issued for a vulnerability in the WordPress plugin WP Maps Pro. the vulnerability is an unauthenticated privilege escalation vulnerability (CVE-2026-8732), which can be exploited through the wpgmptempaccess_ajax AJAX Action (a feature that allows web applications to handle asynchronous requests) related to the way threat actors create administrator accounts.
Affected by
- WP Maps Pro version 6.1.0 and earlier.
Workaround
- the vulnerability has been patched in the latest update.
- You should update to WP Maps Pro version 6.1.1 or later.
Notes
- you should follow the instructions on the reference site to update to the latest version of the Vulnerability Patch.