:

WP MAPS PRO BUG LETS HACKERS CREATE ADMIN ACCOUNTS

SECURITY DESK2 MIN READ
FRI, JUN 5, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A vulnerability in the WP Maps Pro WordPress plugin allows attackers to create administrator accounts without authentication. The exploit targets sites running affected versions of the plugin.

Security researchers have identified an active exploitation campaign targeting WordPress sites running vulnerable versions of the WP Maps Pro plugin. The flaw enables unauthenticated attackers to generate rogue administrator accounts, granting full control over compromised websites. The vulnerability allows threat actors to bypass WordPress security mechanisms entirely. Once admin access is obtained, attackers can modify site content, install malicious plugins, steal data, or use the compromised server for further attacks. What You Need to Know The WP Maps Pro plugin is used to display maps and location data on WordPress sites. The plugin's popularity makes it an attractive target for large-scale exploitation campaigns. Sites remain vulnerable until they upgrade to a patched version. Website administrators should immediately check their installed plugins and verify the version number against the plugin's official repository. Recommended Actions WordPress users should: - Update WP Maps Pro to the latest version immediately - Review administrator accounts for unauthorized entries - Check access logs for suspicious activity - Consider temporarily disabling the plugin if patches are unavailable - Enable two-factor authentication on all admin accounts The plugin developers have released security updates addressing the flaw. Users who cannot update immediately should deactivate the plugin until patched versions are deployed. This incident underscores the ongoing risk posed by third-party WordPress plugins. Regular security audits, timely updates, and careful plugin selection remain essential for site security. Website owners should regularly monitor official WordPress security advisories and plugin vendor announcements for vulnerability disclosures.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

India's national school exam board acknowledged vulnerabilities in its online grading system after a teenage cybersecurity researcher discovered the weaknesses. The board said it has contained the issues affecting one of the country's most critical school-leaving exams.

1H AGOSecurity Desk

Security researchers have identified that Cloudflare's Turnstile CAPTCHA system collects WebGL data capable of fingerprinting devices, raising privacy concerns about the supposedly privacy-focused verification service.

1H AGOIndustry Desk

A security researcher has published technical documentation on parallel reconstruction of lawful TLS wiretapping, demonstrating how encrypted traffic can be decrypted in compliance with court orders. The post has generated significant discussion in the security community.

2H AGOIndustry Desk

Palo Alto Networks has confirmed that hackers are actively exploiting CVE-2026-0257, an authentication bypass vulnerability in GlobalProtect VPN, to breach corporate networks.

4H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.