CVE-2026-17032: Unknown Google-Maps-Easy-Pro

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.

Affected products

  • Unknown Google-Maps-Easy-Pro: from 1.6.9, before 1.7.0 (fixed in 1.7.0)
  • Unknown Supsystic-Gallery-Pro: from 2.10.9, before 2.11.1 (fixed in 2.11.1)
  • Unknown Tables-Generator-Pro: from 1.9.20, before 1.10.1 (fixed in 1.10.1)

Published 2026-08-06. Last modified 2026-08-26.