Stored Cross-Site Scripting Vulnerability in WP Get The Table Plugin for WordPress
CVE-2025-6387
6.4MEDIUM
What is CVE-2025-6387?
The WP Get The Table plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping in the 'url' parameter. This vulnerability allows authenticated attackers with Contributor-level access and above to inject malicious web scripts into pages, which are executed when users access the affected content. The flaw poses a significant risk to user data and site integrity, enabling potential exploitation by malicious actors.
Affected Version(s)
WP Get The Table * <= 1.5