CVE-2026-17032

Supsystic · Google Maps Easy Pro, Supsystic Gallery Pro, Tables Generator Pro

Multiple Supsystic Pro plugins were distributed with malicious code via a compromised update server, allowing unauthenticated attackers to steal sensitive data and gain control of affected sites.

Executive summary

A supply chain compromise affecting multiple Supsystic Pro plugins allows unauthenticated attackers to execute malicious payloads and exfiltrate sensitive data from affected websites.

Vulnerability

This is a hidden functionality vulnerability resulting from a compromised update server. Unauthenticated attackers can leverage the malicious code injected into these plugins to deploy second-stage payloads, leading to full site takeover and credential theft.

Business impact

The impact of this vulnerability is critical, as it provides attackers with the ability to exfiltrate database contents, including user credentials and sensitive business information. The severity is compounded by the fact that the malicious code is delivered through a legitimate update channel, potentially impacting all users who performed an automated update. The CVSS score of 9.8 reflects the high probability of total system compromise.

Remediation

Immediate Action: Update the affected Supsystic plugins to the latest versions provided by the vendor to remove the malicious payload.

Proactive Monitoring: Audit database logs for unusual query patterns and monitor administrative account activity for signs of unauthorized access or credential misuse.

Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets to block known malicious traffic patterns associated with these plugins until the updates are fully applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations using any of the listed Supsystic Pro plugins must verify their current version and update immediately. Because this is a supply chain compromise, it is highly recommended to perform a security audit of the affected servers to ensure no persistent backdoors were installed during the period of vulnerability.