Impact
A compromised vendor update server for multiple Supsystic Pro plugins was used to distribute malicious code, allowing unauthenticated attackers to embed a backdoor that injects a second‑stage payload capable of exfiltrating credentials and other sensitive data while granting full control of the affected websites. This side‑channel bypasses any authentication requirements, enabling attackers to gain remote code execution on any site running the infected plugins.
Affected Systems
The vulnerability impacts Supsystic Pro plugins, specifically Google Maps Easy Pro, Supsystic Gallery Pro, and Tables Generator Pro. No specific version information is disclosed, so all installed instances of these plugins are potentially affected until verified otherwise.
Risk and Exploitability
Risk is high due to the critical CVSS score of 9.8 and the ability for unauthenticated attackers to gain full site compromise. The exploitation hinges on the vulnerability in the plugin update mechanism, which can be triggered with minimal interaction from the attacker. Given the persistence of the second‑stage payload and the lack of obvious mitigation, the overall risk to any site running these plugins should be treated as critical until resolved.
OpenCVE Enrichment