Affected Systems
WP Maps Pro WordPress plugin (all versions prior to patch). Over 15,000 installations via Envato Market. Affects WordPress sites using this plugin for Google Maps integration.
Exploitation Status
Active exploitation confirmed. Threat actors are creating unauthorized administrator accounts on vulnerable WordPress sites in the wild.
Business Impact
Complete site compromise via unauthorized admin account creation. Attackers gain full administrative control, enabling malware injection, data theft, defacement, SEO spam, or use as attack infrastructure. No CVE assigned yet, limiting threat intelligence correlation. Plugin distributed via Envato Market complicates patch distribution and version tracking.
Urgency
🔴 Immediate
Recommended Actions
- Immediately audit all WordPress sites for WP Maps Pro plugin installation and check for unauthorized administrator accounts in wp_users table
- Disable or remove WP Maps Pro plugin until vendor releases and confirms patched version
- Review WordPress access logs and authentication events for suspicious admin account creation activity
- If unauthorized accounts found, perform full incident response: isolate site, review file integrity, check for webshells in wp-content/uploads and theme directories
- Monitor Envato Market and WP Maps Pro vendor channels for security update and apply immediately when available
