Skip to content
CRITICAL: CVE-2026-8935 (CVSS 9.8) — multiple products

CRITICAL: CVE-2026-8935 (CVSS 9.8) — multiple products

Lyrie.Ai June 16, 2026

The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionally creates an administrator account and returns a magic-login URL granting interactive admin access.

_Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation._

A vulnerability of this severity is exactly what Lyrie's anti-rogue-AI defense is built for: continuous, autonomous monitoring that doesn't wait for human reaction time.

Extracted Entities

Attack Types (1)

CVEs (1)

MITRE ATT&CK (1)

Platforms (1)