CVE-2022-2114: Data Tables Generator by Supsystic < 1.10.20 - Admin+ Stored Cross-Site Scripting
The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of The Data Tables Generator by Supsystic WordPress plugin?
The vulnerability ID of The Data Tables Generator by Supsystic WordPress plugin is CVE-2022-2114.
What is the severity of CVE-2022-2114?
The severity of CVE-2022-2114 is medium, with a severity value of 4.8.
What is the affected version of The Data Tables Generator by Supsystic WordPress plugin?
The affected version of The Data Tables Generator by Supsystic WordPress plugin is version 1.10.20 and earlier.
What is the impact of CVE-2022-2114?
The impact of CVE-2022-2114 is that high privilege users, such as admin, could perform Stored Cross-Site Scripting (XSS) attacks.
How can I mitigate the vulnerability in The Data Tables Generator by Supsystic WordPress plugin?
To mitigate the vulnerability, update The Data Tables Generator by Supsystic WordPress plugin to version 1.10.20 or later.