Description
WordPress Plugin wpDataTables-WordPress Data Table, Dynamic Tables & Table Charts (Premium) is prone to multiple vulnerabilities, including SQL injection and security bypass vulnerabilities. Exploiting these issues may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database, or to perform otherwise restricted actions and subsequently access or delete the data of another user. WordPress Plugin wpDataTables-WordPress Data Table, Dynamic Tables & Table Charts (Premium) version 3.4.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.4.2 or latest
References
Related Vulnerabilities
MySQL CVE-2021-35537 Vulnerability (CVE-2021-35537)
WordPress Plugin WP Symposium Cross-Site Scripting (11.11.26)
Jboss EAP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-0248)
Envoy Proxy Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2024-45806)