{"cve":"CVE-2026-73533","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"unaffected","versions":null}],"enrichment":{"confidence":80.0,"confidence_source":"inferred","scores":[{"score":80.0,"source":"inferred"},{"score":100.0,"source":"matching"}]},"product":"wordpress","vendor":"wordpress"},{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"5.2.11"}}],"enrichment":{"confidence":93.0,"confidence_source":"matching","scores":[{"score":95.0,"source":"inferred"},{"score":93.0,"source":"matching"}]},"original":{"product":"Ninja Tables Pro","source":"cna","vendor":"WPManageNinja"},"product":"ninja_tables","vendor":"wpmanageninja"}],"created":"2026-08-13T17:45:03.677708+00:00","updated":"2026-08-14T10:00:03.920049+00:00","vendors":["wordpress","wordpress$PRODUCT$wordpress","wpmanageninja","wpmanageninja$PRODUCT$ninja_tables"]},"epss":{"score":0.00649},"mitre":{"cpes":["cpe:2.3:a:wpmanageninja:ninja_tables:5.2.11:*:*:*:*:wordpress:*:*"],"created":"2026-08-13T16:00:48.030000+00:00","description":"Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}},"mitre_repo_path":"cves/2026/73xxx/CVE-2026-73533.json","references":["https://wordpress.org/plugins/ninja-tables/","https://wpmanageninja.com/security-incident-on-31-july-2026/","https://www.vulncheck.com/advisories/ninja-tables-pro-embedded-malicious-code-via-tampered-plugin-build"],"title":"Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build","updated":"2026-08-17T15:08:31.482000+00:00","vendors":["wpmanageninja","wpmanageninja$PRODUCT$ninja_tables"],"weaknesses":["CWE-506"]},"nvd":{"cpes":[],"created":"2026-08-13T16:19:05.620000+00:00","description":"Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2026/CVE-2026-73533.json","references":["https://wordpress.org/plugins/ninja-tables/","https://wpmanageninja.com/security-incident-on-31-july-2026/","https://www.vulncheck.com/advisories/ninja-tables-pro-embedded-malicious-code-via-tampered-plugin-build"],"title":null,"updated":"2026-09-09T20:35:08.537000+00:00","vendors":[],"weaknesses":["CWE-506"]},"opencve":{"changes":[{"created":"2026-08-13T16:15:00+00:00","data":[{"details":{"new":"Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.","old":null},"type":"description"},{"details":{"new":"Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build","old":null},"type":"title"},{"details":{"added":["CWE-506"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://wordpress.org/plugins/ninja-tables/","https://wpmanageninja.com/security-incident-on-31-july-2026/","https://www.vulncheck.com/advisories/ninja-tables-pro-embedded-malicious-code-via-tampered-plugin-build"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"7e621902-1c64-4b09-9609-ff70792220dc"},{"created":"2026-08-14T10:15:00+00:00","data":[{"details":["wordpress","wordpress$PRODUCT$wordpress","wpmanageninja","wpmanageninja$PRODUCT$ninja_tables"],"type":"first_time"},{"details":{"added":["wordpress","wordpress$PRODUCT$wordpress","wpmanageninja","wpmanageninja$PRODUCT$ninja_tables"],"removed":[]},"type":"vendors"}],"id":"e00cd24b-a535-4af3-81b5-7c02960bf980"},{"created":"2026-08-14T17:15:00+00:00","data":[{"details":{"added":["cpe:2.3:a:wpmanageninja:ninja_tables:5.2.11:*:*:*:*:wordpress:*:*"],"removed":[]},"type":"cpes"}],"id":"e3bd0dac-fa48-4c8d-9799-d17cd105d6d9"},{"created":"2026-08-17T16:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"b7670027-d937-4450-92ef-c87b04de4daf"}],"cpes":{"data":["cpe:2.3:a:wpmanageninja:ninja_tables:5.2.11:*:*:*:*:wordpress:*:*"],"providers":["mitre"]},"created":{"data":"2026-08-13T16:00:48.030000+00:00","provider":"mitre"},"description":{"data":"Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},"provider":"mitre"},"epss":{"data":{"score":0.00649},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://wordpress.org/plugins/ninja-tables/","https://wpmanageninja.com/security-incident-on-31-july-2026/","https://www.vulncheck.com/advisories/ninja-tables-pro-embedded-malicious-code-via-tampered-plugin-build"],"providers":["mitre","nvd"]},"title":{"data":"Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build","provider":"mitre"},"updated":{"data":"2026-08-17T15:16:57.857000+00:00","provider":"nvd"},"vendors":{"data":["wordpress","wordpress$PRODUCT$wordpress","wpmanageninja","wpmanageninja$PRODUCT$ninja_tables"],"providers":["mitre","enrichment"]},"weaknesses":{"data":["CWE-506"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2026-08-13T16:00:48.030000+00:00","description":"Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":"Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build","updated":"2026-08-17T15:08:02.680000+00:00","vendors":[],"vulnrichment_repo_path":"2026/73xxx/CVE-2026-73533.json","weaknesses":[]}}