Critical vulnerability in WordPress plugin WP Maps Pro under attack
A critical vulnerability has been disclosed in WP Maps Pro, a premium WordPress plugin used to create interactive maps with Google Maps and OpenStreetMap. The plugin has more than 15,000 sales on Envato Market. Tracked as CVE-2026-8732 with a CVSS score of 9.8, it affects all versions up to and including 6.1.0 and allows unauthenticated attackers to create new administrator accounts on vulnerable sites, which can lead to complete site takeover. The flaw was found by security researcher David Brown and reported through the Wordfence Bug Bounty Program, and threat actors have already been observed attempting to exploit it. Administrators should update to version 6.1.1 or later as soon as possible and review their sites for unexpected administrator accounts.
What this means for your organisation
For many organisations the website is the most visible expression of the brand, and a takeover can be used to publish false content, redirect visitors to malicious material or extract data from forms. Plugins are the most common entry point in WordPress, and premium plugins are often updated manually because they sit outside the standard update channels. That makes it a question of who actually owns the site in practice.
Berigo recommends
- Update WP Maps Pro to version 6.1.1 or later immediately.
- Review the list of administrator users and remove any account that cannot be explained.
- Clarify who owns updating of the site and its plugins, internally or at a supplier.
- Remove plugins no longer in active use rather than leaving them installed but disabled.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch