Impact
The vulnerability arises from a tampered plugin build of Ninja Tables Pro 5.2.11, which embeds malicious PHP code. The rogue file defines a backdoor REST API endpoint, drops persistent PHP files into the mu-plugins and uploads directories, installs a passwordless administrator account, and registers scheduled tasks that remain even after plugin removal. This allows an attacker to maintain long‑term access, execute arbitrary code, and evade removal efforts, directly compromising confidentiality, integrity, and availability of the WordPress site.
Affected Systems
WordPress sites using the Ninja Tables Pro plugin, specifically version 5.2.11, are affected. This includes any installations that received the compromised update from the decommissioned update server.
Risk and Exploitability
The CVSS score of 9.3 indicates high severity. The EPSS score is not available, but the instance is not listed in CISA's KEV catalog, suggesting no known widespread exploitation yet. The likely attack vector is a compromised plugin update mechanism; an attacker would need to tamper with the build or serve it through the update server, which is inferred from the description.
OpenCVE Enrichment