CVE-2026-8732: WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action

Published May 29, 2026
·
Updated

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmptempaccessajax AJAX action being registered with wpajaxnopriv and protected only by a nonce check using the fc-call-nonce nonce, which is publicly embedded into every frontend page via wplocalizescript as the nonce field of the wpgmplocal JavaScript object, rendering the check ineffective as an access control mechanism. This makes it possible for unauthenticated attackers to invoke the wpgmptempaccesssupport handler with checktemp=false, which unconditionally creates a new WordPress user with the hardcoded role of administrator via wpinsertuser() and returns a magic login URL that, when visited, calls wpsetauthcookie() to fully authenticate the attacker as the newly created administrator, resulting in complete site takeover.

Affected Software

1 affected component
WP Maps WP Maps Pro<=6.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade WordPress plugin: WP Maps Pro to a version that resolves this vulnerability.

    Fixed in 6.1.0
  2. Configuration

    Ensure wpgmp_temp_access_support does not proceed with user creation when check_temp=false; require the intended authenticated/authorized condition rather than relying on the fc-call-nonce nonce embedded via wp_localize_script.

    WP Maps Pro wpgmp_temp_access_support handler (check_temp) = true
  3. Compensating control

    Restrict unauthenticated access to the affected WordPress AJAX endpoint(s) by blocking requests to wpgmp_temp_access_ajax / wpgmp_temp_access_support for non-authenticated users (e.g., via WAF/ACL rules matching the AJAX action).

  4. Operational

    If exploitation occurred, immediately remove the attacker-created administrator account(s) and rotate any exposed credentials/tokens used by the site admins.

Event History

May 29, 2026
CVE Published
via MITRE·05:32 AM
Data Sourced
via MITRE·05:32 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
May 31, 2026
News Published
via BleepingComputer·02:06 PM
News Published
via BleepingComputer·02:15 PM
Jul 3, 58550
Event
via FIRST·10:53 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-8732?

CVE-2026-8732 has a critical severity rating of 9.8.

2

How do I fix CVE-2026-8732?

To fix CVE-2026-8732, update the WP Maps Pro plugin to version 6.1.1 or later.

3

What type of vulnerability is CVE-2026-8732?

CVE-2026-8732 is a privilege escalation vulnerability that allows unauthenticated users to create administrator accounts.

4

Which versions of WP Maps Pro are affected by CVE-2026-8732?

All versions of WP Maps Pro up to and including 6.1.0 are affected by CVE-2026-8732.

5

What is the attack vector for CVE-2026-8732?

CVE-2026-8732 can be exploited remotely without authentication due to the wpgmp_temp_access_ajax AJAX action.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203