Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-73533: Ninja Tables Pro Malicious Code Injection

CVE-2026-73533 · published 21 days ago
Summary

Ninja Tables Pro, a WordPress plugin, contains a critical security flaw that allows malicious code to be injected and executed on a website. This can lead to unauthorized access, data theft, and other security issues. To protect your site, update Ninja Tables Pro to the latest version and consider scanning for any potential malware or backdoors.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
wpmanageninja ninja tables pro 5.2.11
Original advisory text
Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.
Severity
9.3 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-506Embedded Malicious Code
Timeline
Published13 Aug 2026
Updated3 Sep 2026
First seen13 Aug 2026
Sources
CVE-2026-73533 · MITRE
Monitor software like this
Free during beta