Description
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell 'data' Value via updateRows Action in all versions up to, and including, 1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable by Subscriber-level users when an administrator has added their role to the plugin's 'access_roles' setting, which is a documented and explicitly supported plugin feature that grants lower-privileged users access to the dtgs_nonce required to reach the vulnerable updateRows action handler.
Published: 2026-10-10
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting (arbitrary script execution)
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the Data Tables Generator by Supsystic plugin for WordPress and allows authenticated users with subscriber-level access (or higher) to store malicious JavaScript code in the 'data' value of a table cell. When the updateRows action is invoked, the plugin fails to sanitize or escape this content, resulting in stored Cross‑Site Scripting. An attacker can thereby cause arbitrary script execution in the browsers of any visitor who views the affected table, potentially exfiltrating credentials, cookies, or performing phishing attacks.

Affected Systems

All WordPress installations running the Data Tables Generator by Supsystic plugin version 1.15.1 or earlier are impacted. The plugin, developed by supsysticcom, is distributed as a WordPress plugin and can be installed on any WordPress site. Only the specific plugin version range – 1.15.1 and earlier – carries the flaw; newer releases after 1.15.1 are not affected.

Risk and Exploitability

The CVSS v3 rating of 6.4 identifies a moderate level of risk. Since the EPSS score is not available, the exploitation probability cannot be quantified, but the vulnerability requires authenticated access and the submission of crafted input via the updateRows endpoint. It is further contingent on an administrator having granted subscriber-level users access to the plugin’s 'access_roles', a configuration that is optional. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation campaigns. Therefore, the risk is moderate, with exploitation possible in environments where subscriber access is enabled for this plugin.

Generated by OpenCVE AI on October 10, 2026 at 05:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Data Tables Generator by Supsystic plugin to a version newer than 1.15.1, ensuring the vendor published patch is applied.
  • Limit the plugin’s 'access_roles' setting so subscriber‑level users cannot access the updateRows action; restrict access to administrators only.
  • Audit existing tables for injected content in 'data' fields and remove or encode any malicious scripts.

Generated by OpenCVE AI on October 10, 2026 at 05:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Description The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell 'data' Value via updateRows Action in all versions up to, and including, 1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable by Subscriber-level users when an administrator has added their role to the plugin's 'access_roles' setting, which is a documented and explicitly supported plugin feature that grants lower-privileged users access to the dtgs_nonce required to reach the vulnerable updateRows action handler.
Title Data Tables Generator by Supsystic <= 1.15.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Table Cell 'data' Value via updateRows Action
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T04:26:42.279Z

Reserved: 2026-09-23T14:41:42.517Z

Link: CVE-2026-96648

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T05:16:40.533

Modified: 2026-10-10T05:16:40.533

Link: CVE-2026-96648

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T05:30:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')