WP Maps Pro Privilege Escalation Admin Account Creation (CVE-2026-8732) | MSSP Advisory
CriticalHigh Confidence
DateJune 1, 2026
CVECVE-2026-8732
CVSS Score9.8
📋Executive Summary
WP Maps Pro WordPress plugin versions 6.1.0 and below contain a critical privilege escalation flaw (CVE-2026-8732) that allows unauthenticated attackers to create administrative accounts and take complete control of websites. The vulnerability stems from a poorly implemented temporary access feature for support staff that bypasses authentication checks. Wordfence has already blocked 2,858 active exploitation attempts in 24 hours.
⚠️Why It Matters for MSSPs
Your clients running WordPress sites with WP Maps Pro are getting compromised right now while you read this, creating backdoor admin accounts that persist after the initial breach. WordPress compromises typically spread laterally through shared hosting environments and can expose client data that falls under your security responsibility. Active exploitation means this is not theoretical risk.
✅Recommended Action
Contact every client running WordPress immediately to audit for WP Maps Pro installations and force update to version 6.1.1 or remove the plugin entirely within 24 hours.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Vulnerability Disclosure
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.