CVE-2026-73533 (matched: php)

  • Sunday, 16th August, 2026
  • 10:08am

A security issue affects version 5.2.11 of the Ninja Tables Pro WordPress plugin. The compromised version of the plugin was distributed via a decommissioned, no longer official update server for the tool, so users who installed or updated to this specific version through that old server may have received a tampered, malicious copy instead of the legitimate, safe release.

The tampered plugin includes hidden harmful code that gives attackers full unauthorized control of affected websites. It sets up a secret entry point for attackers to access and manipulate the site, drops hidden files that remain on the server even if the plugin is later deleted, creates a hidden administrator account with no password that attackers can use to log in, and sets up hidden automated tasks that continue running even after the plugin is removed.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-73533

« Back