Ninja Tables Pro 5.2.11 存在一个嵌入式恶意代码漏洞,该漏洞通过一个被篡改的插件构建版本引入,该构建版本通过已停用的更新服务器提供。篡改后的构建版本引入了一个恶意 PHP 文件(app/Library/updater/NinjaTableDataSync.php),该文件创建了一个后门 REST API 端点,在 mu-plugins 和 uploads 目录中植入持久化的 PHP 文件,安装了一个无需密码的管理员账户,并注册了即使插件被移除后仍能持续运行的定时任务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| WPManageNinja | Ninja Tables Pro | 5.2.11 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WPManageNinja | Ninja Tables Pro | 5.2.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73532 | 9.8 CRITICAL | Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build |
| CVE-2026-18146 | 7.2 HIGH | Fluent Forms <= 6.2.11 - Unauthenticated Stored Cross-Site Scripting via Notification Smar |
| CVE-2026-66467 | 6.5 MEDIUM | WordPress FluentCommunity plugin <= 2.7.5 - Cross Site Scripting (XSS) vulnerability |
No comments yet