CVE-2026-17032
Received Received - Intake

Unauthenticated Code Execution in Supsystic Pro Plugins

Vulnerability report for CVE-2026-17032, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WPScan

Description

Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
supsystic pro *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Multiple Supsystic Pro plugins were distributed with malicious code via a compromised update server. This allowed unauthenticated attackers to deploy a second-stage payload that steals credentials and sensitive data, and gives full control over affected websites.

Impact Analysis

Attackers can steal login credentials, sensitive data, and gain full control of your website. This could lead to data breaches, unauthorized access, and potential defacement or misuse of your site.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR and HIPAA requirements for data protection and security. Organizations may face fines or legal consequences for non-compliance.

Mitigation Strategies

Immediately remove any Supsystic Pro plugins from your system. Audit all installed plugins and themes for unauthorized changes or suspicious files. Reset all credentials, including database, admin, and user passwords. Monitor network traffic for unusual data exfiltration attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17032. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart