Horizon Alert
Summary of the vulnerability and why it matters
A critical security vulnerability has been identified in the WP Maps Pro WordPress plugin, affecting all versions prior to 6.1.0. This issue allows unauthenticated attackers to create a new administrator account on a WordPress site, potentially leading to a complete takeover of the website. The vulnerability is exploitable remotely without any user interaction.
- Attackers can create admin accounts on WordPress sites.
- Site takeover is possible if the plugin is in use.
- Confirm plugin relevance and verify exposure on your sites.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can create a new administrator account on a WordPress site by exploiting a flaw in the WP Maps Pro plugin. The attacker triggers this by sending a request to a specific AJAX action, bypassing security checks due to a hardcoded nonce. This grants them immediate administrative access, enabling a complete site takeover.
- Publicly accessible AJAX endpoint.
- Unconditional administrator account creation.
- Complete website control.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, unauthenticated attackers could create new administrator accounts on a WordPress site, potentially leading to a complete site takeover.
- Administrator user accounts.
- Unauthenticated AJAX action and nonce bypass.
- Complete WordPress site takeover.
Operational Fix
Recommended remediation, mitigation, and detection steps
The WP Maps Pro plugin's privilege escalation vulnerability requires immediate attention from teams managing WordPress sites. The first step is to identify all instances of the affected plugin, determine their exposure, and confirm the business criticality of each site. Once identified, the accountable owner for each site or instance must be located to plan and execute remediation.
- WordPress site owners should own the issue.
- Verify plugin presence and public accessibility.
- Plan remediation based on site criticality.