Attackers Hammer WP Maps Pro Flaw to Mint Admin Accounts on WordPress Sites

A critical bug in the 15,000-install Envato plugin is being weaponized in the wild to seed rogue administrators.

ThreatVectr Newsdesk· 3 min read
Attackers Hammer WP Maps Pro Flaw to Mint Admin Accounts on WordPress Sites
Share

Threat actors are actively exploiting a critical vulnerability in WP Maps Pro, a commercial WordPress plugin sold through the Envato Market, to plant administrator accounts on vulnerable sites.

The plugin has logged more than 15,000 sales on Envato. It lets site owners embed customizable Google Maps and OpenStreetMap views, complete with markers, listings, and location-aware features. That installed base is now the attack surface.

The flaw is rated critical. Exploitation does not require authentication, and successful attacks let an unauthenticated visitor escalate straight to full administrator on the target site. From there, the rest is routine: backdoor uploads, SEO spam injection, redirects to scam infrastructure, and data theft from any membership or commerce extension running alongside.

The attack pattern is familiar to anyone who watches the WordPress plugin ecosystem. A premium plugin with strong sales numbers ships a vulnerable endpoint. Researchers or vendors publish a fix. Mass scanning begins within hours, often before site owners have noticed an update is available — and Envato-distributed plugins are notoriously slow to propagate patches because there is no central auto-update channel comparable to the wordpress.org repository.

In this case, exploitation telemetry shows attackers probing the affected endpoints and attempting account creation against sites that have not yet patched. Once a rogue admin lands, operators typically rename the account to blend with legitimate users and add a secondary email for persistence.

Who is behind the activity is not yet attributed. The technique — automated mass exploitation followed by admin provisioning — is the standard playbook for the financially motivated crews that monetize compromised WordPress estates through traffic redirection and credit card skimming on WooCommerce stores. Some of those same access brokers later resell footholds to ransomware affiliates targeting the underlying hosting environments.

WP Maps Pro buyers should assume sites are exposed until proven otherwise. Recommended steps:

  • Update WP Maps Pro to the latest version available through CodeCanyon immediately.
  • Audit the WordPress users table for administrator accounts created in the last 30 days, particularly any with unfamiliar email domains.
  • Review the wp_options table and active plugin list for unexpected additions.
  • Rotate all administrator passwords and invalidate active sessions.

Indicators of compromise circulating in researcher channels include admin usernames following randomized patterns and login activity from hosting-provider IP ranges associated with prior WordPress mass-exploitation campaigns.

No ransom demands are tied to this activity directly. The monetization comes downstream, through the resale of access and the parasitic traffic that compromised sites generate. For affected site operators, the practical cost is the same: incident response, customer notification where personal data is involved, and the slow work of rebuilding search-engine trust after a redirect campaign.

Threat Vectr will update as patch adoption data and attribution firm up.

© 2026 Threat Vectr