Multiple Supsystic Pro Plugins <= 1.6.0 - Backdoored Software via Compromised Vendor Software
criticalMultiple Supsystic Pro plugins for WordPress contain backdoors in various versions. This is due to the vendors update server getting compromised. This makes it possible for unauthenticated attackers to gain backdoor remote code execution on sites running the plugins.
- CVSS:
- 9.8 (Wordfence)
- Affected:
- 2.10.9 – 2.10.9
- Fixed in:
- 2.10.11
- Disclosed:
- Jul 24, 2026