The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionally creates an administrator account and returns a magic-login URL granting interactive admin access.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
WP MAPS PRO WordPress plugin versions before 6.1.1 contain a critical vulnerability allowing unauthenticated attackers to create administrator accounts and gain interactive admin access. The flaw stems from an improperly secured AJAX action that accepts a publicly visible nonce (emitted on any page loading the plugin's map script) and unconditionally creates admin accounts without authentication checks. With a CVSS score of 9.8, this affects any WordPress installation using the vulnerable plugin, immediately granting attackers the highest privilege level and complete site compromise. The attack requires no special reconnaissance—the nonce is broadcast to all visitors—making exploitation trivial and exploitation at scale feasible.
While this CVE currently maps to zero MITRE ATT&CK techniques and zero Casky skills, practitioners using Casky's Claude-powered platform with extended reasoning capabilities would detect the attack pattern through behavioral anomaly detection across multiple threat domains. The platform would identify indicators spanning T1078 (Valid Accounts - sudden admin account creation), T1547 (Boot or Logon Autostart Execution - persistent admin establishment), and T1098 (Account Manipulation - unauthorized account provisioning). Security teams would see findings flagged for: unauthenticated AJAX action execution, nonce reuse patterns, administrative account creation from external sources, privilege escalation without credential entry, and magic-link authentication bypassing standard login flows. As threat intelligence maps this vulnerability into MITRE's framework, Casky's skill library will expand to directly address these attack chains, enabling faster detection of similar AJAX security misconfigurations in WordPress ecosystems.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-8935. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation