Embedded Malicious Code Vulnerability in Ninja Tables Pro by WPManageNinja
CVE-2026-73533
9.3CRITICAL
What is CVE-2026-73533?
Ninja Tables Pro version 5.2.11 features an embedded malicious code vulnerability due to a tampered plugin build from a decommissioned update server. This vulnerability introduces a rogue PHP file that establishes a backdoor REST API endpoint. Compromised installations lead to the dropping of persistent PHP files in mu-plugins and uploads directories, creation of a passwordless administrator account, and registration of scheduled tasks that remain even after the plugin is removed.
Affected Version(s)
Ninja Tables Pro 5.2.11
