Impact
The vulnerability resides in the Data Tables Generator by Supsystic plugin for WordPress and allows authenticated users with subscriber-level access (or higher) to store malicious JavaScript code in the 'data' value of a table cell. When the updateRows action is invoked, the plugin fails to sanitize or escape this content, resulting in stored Cross‑Site Scripting. An attacker can thereby cause arbitrary script execution in the browsers of any visitor who views the affected table, potentially exfiltrating credentials, cookies, or performing phishing attacks.
Affected Systems
All WordPress installations running the Data Tables Generator by Supsystic plugin version 1.15.1 or earlier are impacted. The plugin, developed by supsysticcom, is distributed as a WordPress plugin and can be installed on any WordPress site. Only the specific plugin version range – 1.15.1 and earlier – carries the flaw; newer releases after 1.15.1 are not affected.
Risk and Exploitability
The CVSS v3 rating of 6.4 identifies a moderate level of risk. Since the EPSS score is not available, the exploitation probability cannot be quantified, but the vulnerability requires authenticated access and the submission of crafted input via the updateRows endpoint. It is further contingent on an administrator having granted subscriber-level users access to the plugin’s 'access_roles', a configuration that is optional. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation campaigns. Therefore, the risk is moderate, with exploitation possible in environments where subscriber access is enabled for this plugin.
OpenCVE Enrichment