CVE-2026-8732: WP Maps Pro Zero-Day Actively Exploited — One HTTP Request Creates a Rogue Admin Account on 15,000+ WordPress Sites
CVE-2026-8732 is a CVSS 9.8 critical vulnerability in the WP Maps Pro WordPress plugin that lets unauthenticated attackers create administrator accounts with zero credentials — a single HTTP request creates the account, generates a passwordless login URL, and exfiltrates it to the attacker. Wordfence blocked 2,858 exploitation attempts in 24 hours. Over 15,800 commercial installs are in the target window. Patch to version 6.1.1 immediately and audit all admin accounts now.
