Description
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.
Published: 2026-08-13
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from a tampered plugin build of Ninja Tables Pro 5.2.11, which embeds malicious PHP code. The rogue file defines a backdoor REST API endpoint, drops persistent PHP files into the mu-plugins and uploads directories, installs a passwordless administrator account, and registers scheduled tasks that remain even after plugin removal. This allows an attacker to maintain long‑term access, execute arbitrary code, and evade removal efforts, directly compromising confidentiality, integrity, and availability of the WordPress site.

Affected Systems

WordPress sites using the Ninja Tables Pro plugin, specifically version 5.2.11, are affected. This includes any installations that received the compromised update from the decommissioned update server.

Risk and Exploitability

The CVSS score of 9.3 indicates high severity. The EPSS score is not available, but the instance is not listed in CISA's KEV catalog, suggesting no known widespread exploitation yet. The likely attack vector is a compromised plugin update mechanism; an attacker would need to tamper with the build or serve it through the update server, which is inferred from the description.

Generated by OpenCVE AI on August 13, 2026 at 17:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest released version of Ninja Tables Pro (5.2.12 or newer) to eliminate the embedded malicious code.
  • Remove any unauthorized PHP files from the mu-plugins, uploads, and plugin directories, and delete the rogue REST API endpoint (app/Library/updater/NinjaTableDataSync.php).
  • Delete the passwordless administrator account created by the backdoor and remove any scheduled tasks that were registered by the malicious build.

Generated by OpenCVE AI on August 13, 2026 at 17:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.
Title Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build
Weaknesses CWE-506
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-13T16:00:48.030Z

Reserved: 2026-08-12T19:29:19.867Z

Link: CVE-2026-73533

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T16:19:05.620

Modified: 2026-08-13T16:19:05.620

Link: CVE-2026-73533

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T17:45:03Z

Weaknesses