CVE-2020-12076: CSRF
Published Apr 23, 2020
·Updated
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS.
Affected Software
1 affected component
Supsystic Data Tables Generator Wordpress<1.9.92
Event History
Apr 23, 2020
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2020-12076?
CVE-2020-12076 is a vulnerability in the data-tables-generator-by-supsystic plugin for WordPress that lacks CSRF nonce checks for AJAX actions, leading to stored XSS.
2
What is the severity of CVE-2020-12076?
CVE-2020-12076 has a severity rating of critical (8.8).
3
How does CVE-2020-12076 affect Supsystic Data Tables Generator?
CVE-2020-12076 affects Supsystic Data Tables Generator version up to 1.9.92.
4
What is the impact of CVE-2020-12076?
The impact of CVE-2020-12076 is stored XSS.
5
How can I fix CVE-2020-12076?
To fix CVE-2020-12076, update the data-tables-generator-by-supsystic plugin to version 1.9.92 or higher.