CVE-2026-17032
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | google-maps-easy-pro | 1.6.9 < 1.7.0 | affected |
| Unknown | supsystic-gallery-pro | 2.10.9 < 2.11.1 | affected |
| Unknown | tables-generator-pro | 1.9.20 < 1.10.1 | affected |
Weaknesses
- CWE-912 Hidden Functionality
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.