The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionally creates an administrator account and returns a magic-login URL granting interactive admin access.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 15 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-862 |
Mon, 15 Jun 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionally creates an administrator account and returns a magic-login URL granting interactive admin access. | |
| Title | Advanced Google Maps < 6.1.1 - Unauthenticated Administrator Account Creation | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-06-15T06:00:02.334Z
Reserved: 2026-05-19T11:21:38.445Z
Link: CVE-2026-8935
No data.
Status : Received
Published: 2026-06-15T08:16:22.100
Modified: 2026-06-15T08:16:22.100
Link: CVE-2026-8935
No data.
OpenCVE Enrichment
Updated: 2026-06-15T09:30:03Z