CRITICAL: WP Maps Pro Bug (CVE-2026-8732) Spawns Admin Accounts on 15,000 WordPress Sites
A CVSS 9.8 unauthenticated admin account creation flaw in the WP Maps Pro WordPress plugin (CVE-2026-8732) is under active mass exploitation. Wordfence blocked 2,858 attempts and Defiant blocked more than 3,600 within a single 24 hour window. The bug abuses a vendor-support shortcut to mint administrator accounts via an unauthenticated AJAX endpoint. All versions through 6.1.0 are vulnerable. Patch to 6.1.1 and hunt for rogue admins emailed support@flippercode.com.