Impact
The wpDataTables WordPress plugin for versions 6.5.1.1 and earlier contains a Cross‑Site Scripting flaw that does not require authentication. The flaw (CWE‑79) enables an attacker to inject arbitrary client‑side JavaScript into pages served by the plugin. When a visitor loads such a page, the injected script runs under the victim’s browser context, giving the attacker the ability to steal information, deface the site, or perform other client‑side attacks.
Affected Systems
The affected product is Melograno Venture Studio’s wpDataTables plugin for WordPress. All WordPress installations that have the plugin installed with a version of 6.5.1.1 or earlier are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 classifies this vulnerability as high severity, yet the EPSS score of less than 1 % indicates a very low probability of exploitation in the wild. Because the vulnerability is unauthenticated, any site visitor can trigger the XSS payload, and the flaw is not currently listed in CISA’s KEV catalog.
OpenCVE Enrichment