A security issue has been identified in the Ninja Tables Pro WordPress plugin, a tool many site owners use to create and manage tables on their websites. A tampered, unsafe version of the plugin (version 5.2.11) was distributed via a decommissioned, no-longer-active update server for the plugin, rather than the legitimate secure build.
The hidden malicious code embedded in this tampered version creates a secret backdoor entry point that allows unauthorized users to access and control your site. It also drops additional harmful files into your site's storage directories, creates a hidden administrator account for attackers that requires no password to log in, and sets up hidden automated tasks that will remain on your site even if you delete the Ninja Tables Pro plugin entirely.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-73533