CVE-2026-17032

Summary

Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.

Affected Software

VendorProductVersion RangeStatus
Unknowngoogle-maps-easy-pro1.6.9 < 1.7.0affected
Unknownsupsystic-gallery-pro2.10.9 < 2.11.1affected
Unknowntables-generator-pro1.9.20 < 1.10.1affected

Weaknesses

  • CWE-912 Hidden Functionality

References