CVE-2026-73533 (matched: php)

  • Thursday, 13th August, 2026
  • 22:04pm

A security vulnerability affects Ninja Tables Pro version 5.2.11, caused by a tampered, malicious version of the plugin that was distributed through the tool's decommissioned official update server.

When this altered plugin is installed, it runs hidden harmful code. It creates a secret backdoor that lets unauthorized users access your site remotely, plants hidden files in two core site storage folders that stay on your site even if you delete the Ninja Tables plugin later, adds a hidden administrator account that allows someone to log into your site without a password, and sets up hidden automated tasks that continue running even after the plugin is removed.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-73533

« Back