Summary
CVE-2026-17032 is a critical supply-chain compromise (CWE-912, Hidden Functionality) in which multiple Supsystic Pro WordPress plugins — including Google Maps Easy Pro — were distributed with malicious code through the vendor’s compromised update server. An unauthenticated attacker can leverage the embedded backdoor to deploy a second-stage payload, exfiltrate credentials and other sensitive data, and gain full control of affected sites. The issue carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: Backdoored plugin builds were served from the vendor’s compromised update server, embedding hidden malicious functionality directly into the plugin code.
- Trigger conditions: No authentication is required; the malicious code enables deployment of a second-stage payload.
- Attack vector: Network (remote, unauthenticated).
- Impact: Exfiltration of credentials and sensitive data, and complete control over affected WordPress sites.
Affected software
- Google Maps Easy Pro: version 1.6.9 (fixed in 1.7.0)
- Supsystic Gallery Pro: version 2.10.9 (fixed in 2.11.1)
- Tables Generator Pro: version 1.9.20 (fixed in 1.10.1)
Severity
- CVSS v3.1 base score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade to the fixed releases — Google Maps Easy Pro 1.7.0, Supsystic Gallery Pro 2.11.1, or Tables Generator Pro 1.10.1.
- If no patch can be applied: Deactivate and remove the affected plugin versions. Because a backdoor may already have executed, treat impacted sites as compromised: rotate all credentials and secrets, review administrator accounts and scheduled tasks for unauthorized changes, inspect the site for injected files or second-stage payloads, and consider restoring from a known-clean backup taken before installation of the affected version.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
/wp-content/plugins/google-maps-easy/

