Impact
The vulnerability is a Stored Cross‑Site Scripting flaw that allows an attacker with administrator or higher privileges to inject malicious JavaScript into the plugin’s admin settings. The injected script is stored and served to any user who views the affected page, giving the attacker the ability to steal session cookies, deface content, or perform other client‑side attacks. The weakness is a classic input‑validation and output‑encoding failure, identified as CWE‑79.
Affected Systems
WordPress sites that use the TableGen – Data Table Generator plugin version 1.3.1 or earlier, on multisite installations where the unfiltered_html capability is disabled. Only administrators or accounts with equivalent permissions can exploit the flaw.
Risk and Exploitability
The CVSS score of 4.4 indicates low severity. The EPSS score of less than 1% suggests the likelihood of exploitation is very low, and the vulnerability is not listed in the CISA KEV catalog. The attack requires authenticated access as an administrator, so the practical risk is limited to sites with weak role assignments or poorly secured admin accounts, but successful exploitation would compromise the confidentiality, integrity, and availability of end‑user sessions.
OpenCVE Enrichment
EUVD