A security issue has been found in version 5.2.11 of Ninja Tables Pro, a popular WordPress plugin used to add and manage tables on websites. The affected version of the plugin includes hidden harmful code, which was added when a tampered, malicious version of the plugin was distributed via an old update server that the plugin's developers have already shut down.
This hidden code creates secret, unapproved access points to your website, places persistent harmful files in key folders on your hosting account, sets up a hidden administrator account with no password that gives full access to your site's backend, and registers automated hidden tasks that continue running even if you uninstall the Ninja Tables Pro plugin later.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-73533