WP Maps Pro Bug Creates Admin Accounts
Hackers are hitting WordPress sites with the WP Maps Pro plugin to add rogue administrator accounts without any login.
The flaw lets unauthenticated users craft requests that create new admins. Public PoC available. It affects versions up to and including 6.1.0 (patched in 6.1.1) of the plugin.
Any WordPress site running the vulnerable plugin is exposed. That includes sites using maps or location features from the plugin.
Attackers already used it on multiple sites to plant backdoors.
