Cross-site Scripting Vulnerability in WP jQuery DataTable by Biztechc
CVE-2024-56287

6.5MEDIUM

Key Information:

Vendor
Biztechc
Status
WP Jquery Datatable
Vendor
CVE Published:
7 January 2025

Summary

The WP jQuery DataTable plugin by Biztechc is vulnerable to Cross-site Scripting (XSS) attacks due to improper input neutralization during web page generation. This issue allows attackers to execute arbitrary JavaScript in the context of the user's browser, potentially leading to the theft of cookies, session tokens, or other sensitive information. The vulnerability affects versions from n/a up to 4.0.1, making it essential for users to update their installations to mitigate potential risks.

Affected Version(s)

WP jQuery DataTable <= 4.0.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zaim (Patchstack Alliance)
.