CVE-2026-73533: Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73533?
CVE-2026-73533 has a severity rating of 9.8, indicating a critical vulnerability.
How do I fix CVE-2026-73533?
To fix CVE-2026-73533, immediately remove the tampered version of Ninja Tables Pro and install the latest, secure version from a trusted source.
What type of vulnerability is CVE-2026-73533?
CVE-2026-73533 is an embedded malicious code vulnerability caused by a tampered plugin build.
What impact does CVE-2026-73533 have on my site?
CVE-2026-73533 can allow attackers to establish a backdoor REST API endpoint, potentially compromising the entire site.
How was CVE-2026-73533 introduced?
CVE-2026-73533 was introduced through a decommissioned update server that served a tampered build of Ninja Tables Pro.