A security issue has been found in version 5.2.11 of Ninja Tables Pro, a popular WordPress plugin many website owners use to build and manage data tables on their sites. The flaw comes from a tampered, malicious version of the plugin that was distributed through an old, decommissioned update server for the tool.
This malicious version of the plugin includes hidden harmful code that creates a secret backdoor for attackers to access your site, drops hidden files that stay on your site even if you delete the plugin, creates a hidden administrator account with no password that lets anyone log in to your site's backend, and sets up hidden scheduled tasks that continue running even after the plugin is removed.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-73533