Impact
The vulnerability is an improper neutralization of special elements in an SQL command (SQL Injection, CWE-89). A remote attacker can inject malicious SQL through input fields processed by the Ninja Tables plugin, potentially gaining unauthorized read or write access to the database, extracting sensitive data, or altering site content.
Affected Systems
The affected product is the Ninja Tables WordPress plugin by Shahjahan Jewel. Versions up to and including 5.2.3 are vulnerable; all earlier releases are also in scope.
Risk and Exploitability
This issue carries a CVSS score of 7.6, indicating a high impact but requires active exploitation. The EPSS score is below 1%, showing a low probability of exploitation observed to date, and it is not listed in the CISA KEV catalog. Because the plugin is part of a web application, the likely attack vector involves sending crafted requests to the plugin’s endpoints that fail to properly escape user input.
OpenCVE Enrichment