Description
Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.
Published: 2026-08-06
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A compromised vendor update server for multiple Supsystic Pro plugins was used to distribute malicious code, allowing unauthenticated attackers to embed a backdoor that injects a second‑stage payload capable of exfiltrating credentials and other sensitive data while granting full control of the affected websites. This side‑channel bypasses any authentication requirements, enabling attackers to gain remote code execution on any site running the infected plugins.

Affected Systems

The vulnerability impacts Supsystic Pro plugins, specifically Google Maps Easy Pro, Supsystic Gallery Pro, and Tables Generator Pro. No specific version information is disclosed, so all installed instances of these plugins are potentially affected until verified otherwise.

Risk and Exploitability

Risk is high due to the critical CVSS score of 9.8 and the ability for unauthenticated attackers to gain full site compromise. The exploitation hinges on the vulnerability in the plugin update mechanism, which can be triggered with minimal interaction from the attacker. Given the persistence of the second‑stage payload and the lack of obvious mitigation, the overall risk to any site running these plugins should be treated as critical until resolved.

Generated by OpenCVE AI on August 7, 2026 at 01:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Remove all instances of Supsystic Google Maps Easy Pro, Supsystic Gallery Pro, and Tables Generator Pro from the sites.
  • Re‑install the plugins only from the official Supsystic repositories or a verified, trusted source that has not been compromised.
  • Apply any available vendor patches or updated releases that address the backdoor issue, and disable automatic updates for these plugins until the vulnerability is fully resolved.

Generated by OpenCVE AI on August 7, 2026 at 01:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-287
CWE-94

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.
Title Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-06T17:14:39.557Z

Reserved: 2026-07-24T11:57:21.250Z

Link: CVE-2026-17032

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T01:15:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-287

    Improper Authentication

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')