CVE-2026-73533

9.8

WPManageNinja · Ninja Tables Pro

Ninja Tables Pro version 5.2.11 contained a malicious backdoor injected via a tampered plugin build, enabling unauthorized administrative access and persistent system compromise.

Executive summary

A critical supply chain compromise in WPManageNinja Ninja Tables Pro version 5.2.11 has introduced a backdoor allowing remote code execution and unauthorized administrative access.

Vulnerability

This vulnerability involves the distribution of a tampered plugin build containing malicious PHP code. The code facilitates a backdoor REST API, creates a passwordless admin account, and drops persistent backdoors in the server file system that survive plugin uninstallation.

Business impact

The backdoor allows attackers full administrative control over the affected WordPress site, leading to potential data theft, site defacement, and the deployment of further malware. Given the CVSS score of 9.8, this incident poses an extreme risk to the confidentiality, integrity, and availability of the affected web application.

Remediation

Immediate Action: Update Ninja Tables Pro to the latest version immediately, and conduct a forensic scan of the server to purge any malicious files or unauthorized accounts created by the backdoor.

Proactive Monitoring: Regularly audit the WordPress user list for suspicious accounts and scan the server file system for unknown PHP files, particularly in the mu-plugins and uploads folders.

Compensating Controls: Use a WAF to monitor and block unauthorized requests to the WordPress REST API and ensure that file integrity monitoring is active on the server.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this issue cannot be overstated. Administrators must treat this as a total system compromise if the affected version was installed. Immediate patching is mandatory, followed by a thorough investigation of the server environment to ensure all traces of the backdoor have been eradicated, as simple updates may not remove the persistence mechanisms installed by the malicious code.

More WPManageNinja CVEs