CVE-2026-8732 – WP Maps Pro

CVSS 9.8 CRITICAL

“Missing authentication controls in a public-facing plugin can quickly hand attackers elevated access.”

flippercode released a patch for a critical vulnerability affecting WP Maps Pro. CVE-2026-8732 has a CVSS score of 9.8, which is Critical severity.

The vulnerability involves missing authentication for a critical function and is a privilege escalation bug that allows unauthenticated attackers to create a WordPress user with administrative permissions, effectively allowing them to take control of a site. The update strengthens authentication controls and reduces the risk of unauthorized access to administrative functions and plugin management features.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-306
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.