VYPR

Wp Maps Pro

by WordPress

CVEs (4)

  • CVE-2026-8732CriMay 29, 2026
    risk 0.65cvss 9.8epss 0.22

    The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce…

  • CVE-2026-8935CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.00

    The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionally creates an administrator account and returns a magic-login URL granting…

  • CVE-2026-18464HigAug 9, 2026
    risk 0.49cvss 7.5epss 0.00

    The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion…

  • CVE-2026-18465MedAug 9, 2026
    risk 0.42cvss 6.5epss 0.00

    The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not properly validate a user-controlled path before using it in a file inclusion, allowing unauthenticated…