Impact
The WP DataTable plugin for WordPress contains a flaw where user input is not properly neutralized before being incorporated into a web page, allowing DOM‑based Cross‑Site Scripting. An attacker can inject arbitrary client‑side script that will execute in the context of a visitor’s browser. The vulnerability can affect the confidentiality, integrity, or availability of the affected user’s session, or enable defacement of the page in which the script runs.
Affected Systems
This issue applies to the samsk WP DataTable plugin version 0.2.7 and any earlier releases. WordPress sites that have not upgraded beyond 0.2.7 remain vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of below 1% reflects a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a victim to load a page that incorporates malicious user‑controlled data, and the exact delivery method (such as a crafted URL or content entered via the plugin’s interface) is inferred from the nature of the DOM‑based flaw.
OpenCVE Enrichment
EUVD