Description
WordPress Plugin wpDataTables-WordPress Data Table, Dynamic Tables & Table Charts (Premium) is prone to multiple vulnerabilities, including SQL injection and security bypass vulnerabilities. Exploiting these issues may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database, or to perform otherwise restricted actions and subsequently access or delete the data of another user. WordPress Plugin wpDataTables-WordPress Data Table, Dynamic Tables & Table Charts (Premium) version 3.4.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.4.2 or latest
References
Related Vulnerabilities
Squid Improper Input Validation Vulnerability (CVE-2013-4123)
Apache HTTP Server Use After Free Vulnerability (CVE-2017-9789)
Moodle Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2008-5153)
WordPress Plugin Events Widgets For Elementor And The Events Calendar Security Bypass (1.4.3)