Description
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cleanCache() function in all versions up to, and including, 1.10.45. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Published: 2025-11-13
Score: 6.5 Medium
EPSS: 1.9% Low
KEV: No
Impact: Arbitrary file deletion leading to potential remote code execution
Action: Immediate Patch
AI Analysis

Impact

The Data Tables Generator by Supsystic plugin contains insufficient file path validation in its cleanCache() function. This flaw, classified as CWE-22, allows an attacker with authenticated Administrator‑level access to craft requests that delete arbitrary files on the WordPress server. If critical files such as wp-config.php are removed, the attacker can then achieve remote code execution through configuration compromise.

Affected Systems

WordPress installations using the Data Tables Generator by Supsystic plugin, any version up to and including 1.10.45, regardless of minor sub‑versions. The vulnerability applies to all standard installations of the plugin without customization of the cleanCache() routine.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and an EPSS score of 0.01681 indicates an extremely low likelihood of exploitation. The flaw is not listed in CISA KEV, suggesting no currently known widespread exploitation. The attack vector is authenticated, requiring Administrator or higher privilege. An attacker who gains such access can delete arbitrary files; if a core or configuration file is removed, remote code execution or a complete site takeover becomes possible.

Generated by OpenCVE AI on April 27, 2026 at 22:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Data Tables Generator by Supsystic to any version newer than 1.10.45 (latest available).
  • If an update cannot be applied, restrict administrative access to trusted users only and consider disabling the plugin when not needed.
  • Back up the WordPress site, including database and file system, before applying patches or making configuration changes.

Generated by OpenCVE AI on April 27, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Supsystic
Supsystic data Tables Generator
Wordpress
Wordpress wordpress
Vendors & Products Supsystic
Supsystic data Tables Generator
Wordpress
Wordpress wordpress

Thu, 13 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Nov 2025 03:45:00 +0000

Type Values Removed Values Added
Description The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cleanCache() function in all versions up to, and including, 1.10.45. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Title Data Tables Generator by Supsystic <= 1.10.45 - Authenticated (Admin+) Arbitrary File Deletion
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Supsystic Data Tables Generator
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:37:03.374Z

Reserved: 2025-10-22T18:19:15.845Z

Link: CVE-2025-12089

cve-icon Vulnrichment

Updated: 2025-11-13T14:28:19.307Z

cve-icon NVD

Status : Deferred

Published: 2025-11-13T04:15:45.723

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-12089

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-27T23:00:13Z

Weaknesses