Description
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.1 versions.
Published: 2026-07-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The wpDataTables WordPress plugin for versions 6.5.1.1 and earlier contains a Cross‑Site Scripting flaw that does not require authentication. The flaw (CWE‑79) enables an attacker to inject arbitrary client‑side JavaScript into pages served by the plugin. When a visitor loads such a page, the injected script runs under the victim’s browser context, giving the attacker the ability to steal information, deface the site, or perform other client‑side attacks.

Affected Systems

The affected product is Melograno Venture Studio’s wpDataTables plugin for WordPress. All WordPress installations that have the plugin installed with a version of 6.5.1.1 or earlier are vulnerable.

Risk and Exploitability

The CVSS score of 7.1 classifies this vulnerability as high severity, yet the EPSS score of less than 1 % indicates a very low probability of exploitation in the wild. Because the vulnerability is unauthenticated, any site visitor can trigger the XSS payload, and the flaw is not currently listed in CISA’s KEV catalog.

Generated by OpenCVE AI on August 1, 2026 at 21:39 UTC.

Remediation

Vendor Solution

Update the WordPress wpDataTables Plugin to the latest available version (at least 6.5.1.2).


OpenCVE Recommended Actions

  • Upgrade wpDataTables to version 6.5.1.2 or later, the official fix.
  • If an immediate upgrade is not feasible, disable or remove the plugin from the WordPress installation to eliminate the exposure.
  • Implement a stringent Content‑Security‑Policy header to restrict the execution of injected scripts.

Generated by OpenCVE AI on August 1, 2026 at 21:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Melograno Venture Studio
Melograno Venture Studio wpdatatables
Wordpress
Wordpress wordpress
Vendors & Products Melograno Venture Studio
Melograno Venture Studio wpdatatables
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.1 versions.
Title WordPress wpDataTables plugin <= 6.5.1.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Melograno Venture Studio Wpdatatables
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T14:34:19.764Z

Reserved: 2026-06-25T08:03:37.652Z

Link: CVE-2026-57672

cve-icon Vulnrichment

Updated: 2026-07-02T14:34:14.887Z

cve-icon NVD

Status : Deferred

Published: 2026-07-02T12:17:37.873

Modified: 2026-07-02T15:17:09.997

Link: CVE-2026-57672

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T21:45:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')