Sceawere

Vulnerability Detail

CVE-2026-17032UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Supsystic Pro Plugins Supply Chain Compromise

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
1d ago
Vendor
Unknown
Product
google-maps-easy-pro
Attack Type
CWE-912 Hidden Functionality
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-06T22:16:49.237Z",
  "pubdate": "2026-08-06T22:16:49.237Z",
  "executiveSummary": "Multiple Supsystic Pro plugins suffered a critical supply chain compromise resulting from the direct infection of the vendor's software update server with malicious code.\nThis integrity violation enables unauthenticated threat actors to leverage the automated update mechanism to distribute malicious payloads directly to client installations.\nThe primary impact of this compromise includes total administrative takeover of affected WordPress websites, unauthorized credential exfiltration, and the deployment of secondary persistent payloads.\nGiven that the infection vector originates from trusted update channels, traditional perimeter defenses are frequently bypassed, presenting severe risk implications for all organizations utilizing the affected software.\nExploitation requires no prior authentication or specialized privileges from the attacker's perspective, as the malicious code is natively executed via the trusted vendor distribution framework.\nSystem administrators face immediate risks of complete site compromise, data loss, and unauthorized access to underlying server environments unless immediate remediation measures are enacted.",
  "technicalDetails": "The vulnerability stems from an external supply chain compromise rather than a discrete logic flaw in the plugin source code itself; specifically, the vendor's update server infrastructure was breached to distribute modified software packages.\nThe affected components are multiple Supsystic Pro plugins distributed through the compromised update mechanism, exposing network-connected WordPress instances to remote execution vectors.\nAuthentication and privilege requirements for exploitation are effectively bypassed because the malicious payload is delivered via legitimate administrative update channels, requiring zero interaction or credentials from external threat actors.\nThe attack flow proceeds as follows: First, attackers compromise the vendor's update server. Second, when an administrator checks for or applies updates, the compromised server distributes a modified plugin package containing unauthorized malicious code alongside or embedded within the legitimate functionality.\nUpon installation and execution, the injected code acts as a dropper, initiating outbound network connections to retrieve a second-stage payload.\nThe second-stage payload is designed to harvest sensitive data, including database credentials and user session tokens, and exfiltrate this information to attacker-controlled command and control infrastructure.\nPost-exploitation impact includes full administrative control over the affected WordPress instances, allowing the adversary to establish persistence via backdoors, modify core application files, and execute arbitrary code on the underlying host operating system."
}
CVE-2026-17032: Supsystic Pro Plugins Supply Chain Compromise (CRITICAL Severity, CVSS: 9.8) - Sceawere