CVE-2026-8935 PUBLISHED

Advanced Google Maps < 6.1.1 - Unauthenticated Administrator Account Creation

Assigner: WPScan
Reserved: 19.05.2026 Published: 15.06.2026 Updated: 15.06.2026

The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionally creates an administrator account and returns a magic-login URL granting interactive admin access.

Product Status

Vendor Unknown
Product WP MAPS PRO
Versions Default: unaffected
  • affected from 0 to 6.1.1 (excl.)

Credits

  • Erwan LR (WPScan) finder
  • WPScan coordinator

References

Problem Types

  • CWE-269 Improper Privilege Management CWE