Reflected Cross-Site Scripting Vulnerability in wpDataTables Plugin for WordPress
CVE-2024-0591
6.1MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 13 March 2024
Summary
The wpDataTables plugin for WordPress is susceptible to Reflected Cross-Site Scripting due to inadequate sanitization of user input and improper escaping of output. Attackers may leverage this flaw by tricking users into clicking malicious links that execute arbitrary web scripts within the context of the site. This vulnerability affects all versions of the plugin up to 3.4.2.2 and poses a significant risk to the security of websites utilizing this plugin.
Affected Version(s)
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin * <= 3.4.2.4
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Matthew Rollings