{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-73533/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-73533"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ninja Tables Pro (5.2.11)"],"_cs_severities":["critical"],"_cs_tags":["supply-chain","wordpress","webshell","cve-2026-73533"],"_cs_type":"advisory","_cs_vendors":["Ninja Tables"],"content_html":"\u003cp\u003eNinja Tables Pro version 5.2.11 was compromised through a supply chain attack involving a decommissioned update server. This server was leveraged to distribute a tampered plugin build to unsuspecting users. The malicious build contains a rogue PHP file, located at app/Library/updater/NinjaTableDataSync.php, which facilitates unauthorized access by establishing a backdoor REST API endpoint.\u003c/p\u003e\n\u003cp\u003eOnce installed, the malicious code performs several actions to ensure persistence and control over the compromised WordPress environment. It drops persistent PHP files within the 'mu-plugins' and 'uploads' directories, creates a passwordless administrator account, and registers scheduled tasks that persist even if the primary plugin is removed. Defenders must audit their WordPress installations for the presence of this specific file and check for unauthorized administrator accounts or unrecognized files in the 'mu-plugins' directory.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains control of or spoofs a decommissioned update server associated with the Ninja Tables plugin.\u003c/li\u003e\n\u003cli\u003eThe compromised server pushes a tampered version of the Ninja Tables Pro 5.2.11 plugin to clients.\u003c/li\u003e\n\u003cli\u003eThe plugin installation executes the payload, dropping the malicious file app/Library/updater/NinjaTableDataSync.php.\u003c/li\u003e\n\u003cli\u003eThe malicious PHP code activates a backdoor REST API endpoint to receive external commands.\u003c/li\u003e\n\u003cli\u003eThe backdoor drops additional persistent PHP payloads into the WordPress 'mu-plugins' and 'uploads' folders.\u003c/li\u003e\n\u003cli\u003eThe script creates a new, passwordless administrator account to ensure future access.\u003c/li\u003e\n\u003cli\u003eThe script registers scheduled tasks (cron jobs) to maintain persistence across plugin updates or removals.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the established backdoor and administrator account to facilitate ongoing unauthorized access and system manipulation.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for full, unauthenticated administrative control over the affected WordPress environment. This enables the attacker to exfiltrate data, modify site content, or use the compromised site as a platform for further attacks. Given the nature of the persistence mechanisms, cleanup requires manual removal of malicious files and database entries beyond simply updating or deleting the affected plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePerform a file integrity audit on all WordPress installations using Ninja Tables Pro to identify the existence of app/Library/updater/NinjaTableDataSync.php.\u003c/li\u003e\n\u003cli\u003eAudit the 'mu-plugins' directory for any unauthorized PHP files that were not manually installed by your organization.\u003c/li\u003e\n\u003cli\u003eReview all WordPress user accounts for suspicious, passwordless, or unexpected administrator-level accounts.\u003c/li\u003e\n\u003cli\u003eRemove any scheduled tasks (WP-Cron) associated with the Ninja Tables plugin and verify no other rogue tasks remain.\u003c/li\u003e\n\u003cli\u003eUse the Sigma rule provided below to monitor for the creation or execution of files within the 'mu-plugins' path, as this is a common persistence location for web-based attacks.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T16:56:09Z","date_published":"2026-08-13T16:56:09Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ninja-tables-backdoor/","summary":"Ninja Tables Pro version 5.2.11 was compromised via a supply chain attack involving a decommissioned update server that distributed a tampered plugin build containing a PHP backdoor.","title":"Supply Chain Compromise of Ninja Tables Pro via Malicious Update","url":"https://feed.craftedsignal.io/briefs/2026-08-ninja-tables-backdoor/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-73533","version":"https://jsonfeed.org/version/1.1"}