FeedExploreAsk AIAlertsSavedProfile

Categories

AICybersecurityInfrastructureDatabaseTech Updates

Tech news that matters.

FeedExploreAskAlertsSavedProfile
Back to feed
Cybersecurity·CriticalBreaking

Critical WP Maps Pro Flaw Exploited

A cracked shield with the WordPress logo, symbolizing a security vulnerability in the WP Maps Pro plugin.

TL;DR: A critical vulnerability in the WP Maps Pro WordPress plugin is being actively exploited by attackers. The flaw allows unauthorized users to create new administrator accounts, granting them full control over affected websites. The plugin has over 15,000 sales, indicating a significant number of potentially vulnerable sites.

By Neeraj Dhiman·3h ago·1 min read·updated 1h ago
Source

Key facts

Category
Cybersecurity
Impact
Critical
Published
3h ago
Source
The Hacker News

Full summary

A critical, actively exploited flaw in the popular WP Maps Pro plugin allows attackers to create admin accounts and take over WordPress sites.

A critical security vulnerability in the popular WP Maps Pro WordPress plugin is being actively exploited by attackers. The flaw allows unauthorized individuals to create new administrator accounts on websites using the plugin, granting them complete control. This type of vulnerability is particularly dangerous as it provides a direct path for a full site takeover without needing to steal existing credentials. WP Maps Pro, a premium plugin with over 15,000 sales on the Envato Market, is used by businesses to embed customizable maps with advanced location features, making its user base widespread.

The immediate impact for affected site owners is severe. Once an attacker creates a rogue admin account, they can modify content, install malicious code, steal sensitive user data, or use the website's reputation to launch phishing attacks. This poses a significant risk not only to the business's operations and data integrity but also to its customers and brand reputation. Given that the vulnerability is under active exploitation, the threat is not theoretical but an ongoing campaign. All websites running a vulnerable version of the WP Maps Pro plugin are at high risk.

Why it matters

This actively exploited flaw gives attackers a simple way to gain full administrative control over thousands of WordPress sites, leading to potential data theft and site defacement.

Business impact

A compromised website can lead to significant reputational damage, customer data breaches, and financial loss from cleanup efforts and lost business.

⚡ Action needed

An immediate update to the latest version of the WP Maps Pro plugin is required to patch this critical vulnerability. All site administrators should also check for unauthorized user accounts.

Action checklist

  1. 1Immediately update the WP Maps Pro plugin to the latest patched version.
  2. 2Audit all user accounts on your WordPress site for any unauthorized admin accounts.
  3. 3Remove any suspicious or unrecognized user accounts found.
  4. 4Run a security scan to check for backdoors or malware.
  5. 5Review site logs for signs of suspicious activity or unauthorized access.

Tags

#cybersecurity#vulnerability#wordpress#plugin#wp maps pro

Related on Notifire

  • ResearchCritical CVEs of 2026
  • GlossaryCVE
  • ResearchSupply-chain security

✦ Notifire newsletter

Get more Cybersecurity intelligence

Join engineers getting Notifire’s verified tech briefings — short, sourced, and free. No spam, unsubscribe anytime.

The day's most important tech briefings. No spam, unsubscribe anytime.

Primary source: The Hacker News

Part of our research on

  • Critical CVEs of 2026 →

Tech intelligence for engineering teams

Short, verified briefings on AI, cybersecurity, infrastructure, and data — with the analysis and action steps that matter. Every briefing is sourced, fact-checked, and bylined to a named editor.

[email protected]Story tips & corrections welcomeHow we report →

The Notifire briefing

Verified tech intelligence in your inbox — AI, security, infra, and data.

The day's most important tech briefings. No spam, unsubscribe anytime.

Sections

  • AI
  • Cybersecurity
  • Infrastructure
  • Database
  • Tech Updates
  • Web3 & Chains

Newsroom

  • About Notifire
  • Editorial team
  • Editorial standards
  • Methodology
  • AI disclosure
  • Corrections

Resources

  • Explore
  • Research hubs
  • Comparisons
  • Tech glossary
  • FAQ
  • Alerts & watchlists

Follow

  • RSS feed
© 2026 NotifirePrivacyTermsCorrections
An independent, AI-assisted publication. Built at </Alpheric>
IntelligenceLive panel
Live

Top trending

Last 24h

    Popular tags

    Add to watchlist

    +OpenAI+Claude+PostgreSQL+Kubernetes+Cloudflare+AWS+CVE Critical

    Notifire score

    0–100 priority signal — combines impact, freshness, trending velocity, and source credibility.

  1. Atom feed
  2. LinkedIn
  3. X / Twitter
  4. Facebook
  5. Instagram
  6. YouTube