A security issue affects a compromised version of the popular WordPress table plugin Ninja Tables Pro, version 5.2.11. This malicious version of the plugin was distributed through a decommissioned (no longer active) official update server for the tool, so sites that received plugin updates from that old server may have installed the tampered build.
The hidden harmful code in this bad plugin version creates a secret backdoor that lets unauthorized people access your site, drops persistent hidden files in key parts of your site's file system, creates a hidden administrator account with no password that gives attackers full control of your site, and sets up hidden scheduled tasks that stay on your site even if you delete the Ninja Tables Pro plugin later.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-73533