Critical severity9.8NVD Advisory· Published Jun 15, 2026· Updated Jun 15, 2026
CVE-2026-8935
CVE-2026-8935
Description
The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionally creates an administrator account and returns a magic-login URL granting interactive admin access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<6.1.1+ 1 more
- (no CPE)range: <6.1.1
- (no CPE)range: <6.1.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.