PT-2026-49185 · WordPress · Wp Maps Pro
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WP MAPS PRO versions prior to 6.1.1
Description
The plugin registers an unauthenticated AJAX action that allows the creation of an administrator account. By providing a valid nonce, which is publicly available on any frontend page that enqueues the map script, an attacker can unconditionally create an admin account and receive a magic-login URL that provides interactive administrative access.
Recommendations
Update to version 6.1.1 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wp Maps Pro