CyberRota Analysis
AI-GeneratedMultiple Supsystic Pro plugins contain malicious code due to a compromise of the vendor's update server, enabling unauthenticated attackers to execute a second-stage payload that can exfiltrate credentials and sensitive data while granting full control over affected sites. Organizations using these plugins should prioritize immediate remediation to prevent potential data breaches and unauthorized access. This vulnerability is critical and impacts any site utilizing the affected plugins.
Original NVD Description
Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.