Impact
Unauthenticated Cross Site Scripting exists in wpDataTables plugin versions 7.5.1 and earlier. The flaw allows an attacker to inject arbitrary scripts that execute in the browsers of users who view affected pages. This vulnerability is identified as CWE‑79, indicating improper handling of user‑supplied data. The primary impact is that malicious code runs with the privileges of the site’s visitors, which can be used to deface content or exfiltrate data from the visitor’s session context.
Affected Systems
WordPress sites that have installed the wpDataTables plugin version 7.5.1 or older are vulnerable. No other products or versions are listed in the CNA data as affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, and the EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog, but because the attack is unauthenticated and can be triggered by any visitor, the risk of exploitation remains significant for sites that have not applied the upgrade. Official remediation is to upgrade the plugin to version 7.5.2 or later, which removes the vulnerable code.
OpenCVE Enrichment