Impact
The vulnerability allows authenticated users with contributor or higher privileges to inject malicious scripts into the "id" attribute of tables. When a table page containing the malicious attribute is viewed, the browser runs the embedded script, which can hijack user sessions, steal credentials, or deface the site. The weakness is a classic input sanitization failure (CWE‑79) that permits persistent XSS to be stored and later executed for any visitor of the affected page.
Affected Systems
This issue affects the WordPress plugin "Data Tables Generator by Supsystic" version 1.12.03 and earlier. It can be exploited in any WordPress installation that uses a vulnerable instance of the plugin, regardless of host environment.
Risk and Exploitability
The CVSS base score of 6.4 indicates a moderate risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting current exploitation activity is low. However, because the attack requires authenticated contributor-level access, it is limited to roles with write permissions to tables. Once access is achieved, injected scripts execute immediately for any user who views the affected table pages. The impact is confined to client browsers but can compromise end‑user sessions or exfiltrate data. The vulnerability is not exploitable by unauthenticated attackers and there is no public exploit known.
OpenCVE Enrichment