Cross Site Scripting Flaw in wpDataTables by WordPress
CVE-2026-65509

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 August 2026

What is CVE-2026-65509?

A security flaw has been identified in the wpDataTables plugin for WordPress, allowing unauthorized users to perform Cross Site Scripting (XSS) attacks. This vulnerability impacts versions 7.5.1 and earlier, enabling attackers to inject malicious scripts into web applications visited by users. This exploitation can lead to the theft of sensitive information or user session hijacking, posing significant risks to affected websites. It is recommended for users to update to the latest version to mitigate this risk and enhance the overall security of their sites.

Affected Version(s)

wpDataTables <= 7.5.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

VanTastic | Patchstack Bug Bounty Program
.