WePlugins A.I CyberSecurity Scoring
WePlugins
Company Information
Website:https://weplugins.com
Employees number:12
Number of followers:6,012
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:weplugins.com
WePlugins Risk Score (AI oriented)
Between 700 and 749
WePluginsIT Services and IT Consulting
Updated:
29/05/2026
29/05/2026
747/1000
Moderate
Ba
WePlugins Global Score (TPRM)
xxxx
WePluginsIT Services and IT Consulting
Score locked

WePluginsModerate
Current Score
747Ba (MODERATE)
01000
1 incidents
-1 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
748
AUGUST 2026
748
JULY 2026
748
JUNE 2026
747
MAY 2026
747
APRIL 2026
747
MARCH 2026
748
Vulnerability
24 Mar 2026 • WePlugins
Flippercode: WP Maps Pro Vulnerability Exposed 15,000 WordPress Sites to Site Takeover
Critical WP Maps Pro Plugin Vulnerability Allowed Unauthenticated Admin Account Creation
747
CRITICAL-1
WEP1780050340
Critical WP Maps Pro Plugin Vulnerability Allowed Unauthenticated Admin Account Creation
A severe security flaw in the WP Maps Pro WordPress plugin (versions up to 6.1.0) enabled unauthenticated attackers to create administrator accounts, leading to potential full site takeovers. The vulnerability, discovered by security researcher David Brown and reported via the Wordfence Bug Bounty Program on March 24, 2026, affected over 15,000 installations at the time of disclosure.
The flaw stemmed from an improperly secured AJAX action in the plugin’s temporary access feature, originally designed for support staff. The `wpgmp_temp_access_ajax_callback()` function lacked a capability check, allowing unauthenticated users to exploit it. Attackers could trigger the function by bypassing a publicly exposed nonce, then execute `wpgmp_temp_access_support()` to generate a new administrator account with:
- A randomly generated username (e.g., `fc_user_*`),
- The hardcoded email [email protected],
- Full administrator privileges.
The plugin then provided a login URL that authenticated the attacker without requiring a password, granting them unrestricted access to:
- Install malicious plugins,
- Modify themes,
- Inject backdoors,
- Deploy webshells,
- Steal site data.
The vendor patched the issue in WP Maps Pro 6.1.1, released on May 20, 2026, by adding a capability check to restrict the vulnerable endpoint to authenticated administrators. Wordfence provided firewall protection to Premium, Care, and Response users on May 18, 2026, with free users scheduled to receive the same protection on June 17, 2026. The vulnerability was escalated to Envato’s security team on May 16, 2026, after researchers failed to locate direct vendor contact information.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
748
JANUARY 2026
748
DECEMBER 2025
748
NOVEMBER 2025
748
OCTOBER 2025
748
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for WePlugins ??
What was WePlugins's A.I Rankiteo Cyber Score in August 2026 ??
What was WePlugins's A.I Rankiteo Cyber Score in July 2026 ??
What was WePlugins's A.I Rankiteo Cyber Score in June 2026 ??
What was WePlugins's A.I Rankiteo Cyber Score in May 2026 ??
What was WePlugins's A.I Rankiteo Cyber Score in April 2026 ??
What was WePlugins's A.I Rankiteo Cyber Score in March 2026 ??
What was WePlugins's A.I Rankiteo Cyber Score in February 2026 ??
What was WePlugins's A.I Rankiteo Cyber Score in January 2026 ??
What was WePlugins's A.I Rankiteo Cyber Score in December 2025 ??
What was WePlugins's A.I Rankiteo Cyber Score in November 2025 ??
What was WePlugins's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on WePlugins's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with WePlugins ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view WePlugins's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?