Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
WePlugins

WePlugins Vendor Cyber Rating & Cyber Score

weplugins.com

Our mission is to empower WordPress developers worldwide by offering easy-to-use, plug-n-play solutions that save them time and enable them to focus on what they do best.


WePlugins A.I CyberSecurity Scoring

WePlugins
Company Information
Website:https://weplugins.com
Employees number:12
Number of followers:6,012
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:weplugins.com
WePlugins Risk Score (AI oriented)
Between 700 and 749
logo
WePluginsIT Services and IT Consulting
Updated:
29/05/2026
747/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
WePlugins Global Score (TPRM)
xxxx
logo
WePluginsIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

WePlugins
WePluginsModerate
Current Score
747Ba (MODERATE)
01000
1 incidents
-1 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
748Before Incident
AUGUST 2026
748Before Incident
JULY 2026
748Before Incident
JUNE 2026
747Before Incident
MAY 2026
747Before Incident
APRIL 2026
747Before Incident
MARCH 2026
748Before Incident
Vulnerability
24 Mar 2026WePlugins
Flippercode: WP Maps Pro Vulnerability Exposed 15,000 WordPress Sites to Site Takeover

Critical WP Maps Pro Plugin Vulnerability Allowed Unauthenticated Admin Account Creation

747After Incident
CRITICAL-1
WEP1780050340
Critical WP Maps Pro Plugin Vulnerability Allowed Unauthenticated Admin Account Creation A severe security flaw in the WP Maps Pro WordPress plugin (versions up to 6.1.0) enabled unauthenticated attackers to create administrator accounts, leading to potential full site takeovers. The vulnerability, discovered by security researcher David Brown and reported via the Wordfence Bug Bounty Program on March 24, 2026, affected over 15,000 installations at the time of disclosure. The flaw stemmed from an improperly secured AJAX action in the plugin’s temporary access feature, originally designed for support staff. The `wpgmp_temp_access_ajax_callback()` function lacked a capability check, allowing unauthenticated users to exploit it. Attackers could trigger the function by bypassing a publicly exposed nonce, then execute `wpgmp_temp_access_support()` to generate a new administrator account with: - A randomly generated username (e.g., `fc_user_*`), - The hardcoded email [email protected], - Full administrator privileges. The plugin then provided a login URL that authenticated the attacker without requiring a password, granting them unrestricted access to: - Install malicious plugins, - Modify themes, - Inject backdoors, - Deploy webshells, - Steal site data. The vendor patched the issue in WP Maps Pro 6.1.1, released on May 20, 2026, by adding a capability check to restrict the vulnerable endpoint to authenticated administrators. Wordfence provided firewall protection to Premium, Care, and Response users on May 18, 2026, with free users scheduled to receive the same protection on June 17, 2026. The vulnerability was escalated to Envato’s security team on May 16, 2026, after researchers failed to locate direct vendor contact information.
INCIDENT DETAILS -
TYPE
Privilege Escalation
IMPACT
Data Compromised: Site data, including sensitive information if storedSystems Affected: WordPress sites using WP Maps Pro plugin (versions ≤ 6.1.0)Operational Impact: Full site takeover, unauthorized administrative accessBrand Reputation Impact: Potential reputational damage for affected sitesIdentity Theft Risk: High (if PII was stored on compromised sites)Payment Information Risk: High (if payment data was stored on compromised sites)
DATA BREACH
Type Of Data Compromised: Site data, administrative credentials, potentially PII/payment dataSensitivity Of Data: High (administrative access, potential PII/payment data)Personally Identifiable Information: Potential (if stored on compromised sites)
FEBRUARY 2026
748Before Incident
JANUARY 2026
748Before Incident
DECEMBER 2025
748Before Incident
NOVEMBER 2025
748Before Incident
OCTOBER 2025
748Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for WePlugins ?
?
What was WePlugins's A.I Rankiteo Cyber Score in August 2026 ?
?
What was WePlugins's A.I Rankiteo Cyber Score in July 2026 ?
?
What was WePlugins's A.I Rankiteo Cyber Score in June 2026 ?
?
What was WePlugins's A.I Rankiteo Cyber Score in May 2026 ?
?
What was WePlugins's A.I Rankiteo Cyber Score in April 2026 ?
?
What was WePlugins's A.I Rankiteo Cyber Score in March 2026 ?
?
What was WePlugins's A.I Rankiteo Cyber Score in February 2026 ?
?
What was WePlugins's A.I Rankiteo Cyber Score in January 2026 ?
?
What was WePlugins's A.I Rankiteo Cyber Score in December 2025 ?
?
What was WePlugins's A.I Rankiteo Cyber Score in November 2025 ?
?
What was WePlugins's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on WePlugins's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with WePlugins ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view WePlugins's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?