CVE-2026-73533 (matched: php)

  • Saturday, 15th August, 2026
  • 10:05am

A security vulnerability tracked as CVE-2026-73533 has been identified in Ninja Tables Pro, a popular WordPress plugin used to create and manage tables on websites. The issue affects version 5.2.11 of the plugin, which was distributed with hidden malicious code through an old, decommissioned update server that the plugin’s developer no longer operates.

The hidden malicious code creates a secret backdoor that grants unauthorized people full access to your website. It sets up a hidden administrator account with no password for intruders to log in with, drops hidden files that remain on your site even if you delete the Ninja Tables Pro plugin, and creates automatic background tasks that continue running even after the plugin is removed.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-73533

« Back