Impact
The vulnerability is an unauthenticated Cross Site Scripting flaw in the WordPress Ninja Tables plugin versions up to 5.2.9. It allows an attacker to inject arbitrary JavaScript into the plugin’s stored content which is rendered in the browser of any user visiting that page. The flaw is categorized as CWE‑79 and can lead to session hijacking, defacement, or the execution of malicious code in the context of the site’s users.
Affected Systems
The affected product is the WordPress Ninja Tables plugin (WPManageNinja), specifically all releases through 5.2.9. No other WordPress core components or plugins are directly implicated by this specific vulnerability.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score is not available and the issue is not listed in the CISA KEV catalog. Because the flaw is unauthenticated, the attack vector requires an attacker to get the malicious content into a table that is then displayed to a user; once displayed, the injected script runs with the privileges of the visitor’s browser session. There is no known requirement for network access or local privileges beyond the ability to insert table content, making exploitation relatively straightforward if an attacker can add or edit table entries.
OpenCVE Enrichment