Impact
The wpDataTables plugin for WordPress contains an unauthenticated Cross Site Scripting (XSS) vulnerability in versions 6.5.1.1 and earlier. The flaw (CWE‑79) permits an attacker to embed arbitrary client‑side scripts into pages served by the plugin. When a visitor views an affected page, the injected scripts would run in the browser, enabling the attacker to conduct client‑side exploits.
Affected Systems
Melograno Venture Studio’s wpDataTables plugin for WordPress, versions up to and including 6.5.1.1. Any WordPress site that has installed one of these plugin versions is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability, and the EPSS score of less than 1 % suggests a low probability of exploitation, though it remains possible. Attackers need no authentication to trigger the XSS; the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment