CVE-2026-17032 Details
Description
Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.
A backdoor vulnerability has been introduced in multiple Supsystic Pro WordPress plugins, including 'Google Maps Easy Pro' version 1.6.9, 'Supsystic Gallery Pro' version 2.10.9, and 'Tables Generator Pro' version 1.9.20. This vulnerability arose from the vendor's update server being compromised, allowing unauthenticated attackers to inject malicious code. The injected backdoor enables attackers to execute arbitrary commands on the server, create rogue administrator accounts, and exfiltrate sensitive data such as passwords and site information. Additionally, the backdoor forces malicious auto-updates, propagating the infection through the WordPress ecosystem.
Users can update to 'Google Maps Easy Pro' version 1.7.0, 'Supsystic Gallery Pro' version 2.11.1, and 'Tables Generator Pro' version 1.10.1 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 6, 2026CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/7ca5ad30-1792-4014-bfad-88911cd64713/ | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-912 | Hidden Functionality | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Supsystic Google Maps Easy Pro | 1.6.9 (semver) |
CPE
Remediation
| |
| Supsystic Gallery Pro | 2.10.9 (semver) |
CPE
Remediation
| |
| Supsystic Tables Generator Pro | 1.9.20 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |
Volerion