Impact
The WP Get The Table plugin for WordPress is affected by a stored cross‑site scripting flaw that originates from the unchecked ‘url’ parameter. Unsanitized user input is persisted to the database and later rendered without escaping, enabling an authenticated user with Contributor privileges or higher to embed arbitrary JavaScript into plugin pages. When other site visitors load those pages, the injected JavaScript runs within their browser context.
Affected Systems
All releases of WP Get The Table up to and including version 1.5 are impacted. The plugin is distributed through the official WordPress repository under the maintainer jonsisk. WordPress site owners who have installed any of these versions should consider the change a risk until a new fixed release is applied.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate technical severity, while the EPSS score of less than 1% suggests the vulnerability is unlikely to be actively exploited in the wild at the time of analysis. The flaw requires authenticated access; therefore, attackers must first gain Contributor‑level credentials through social engineering or credential compromise. Once in, they can create or modify a plugin page that contains the XSS payload. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD