CVE-2024-12772: Ninja Tables < 5.0.17 - Admin+ Stored XSS
Published Jan 31, 2025
·Updated
The Ninja Tables WordPress plugin before 5.0.17 does not sanitize and escape a parameter before outputting it back in the page when importing a CSV, leading to a Cross Site Scripting vulnerability.
Affected Software
2 affected components
Ninja Tables Ninja Tables<5.0.17
WPManageNinja Ninja Tables Wordpress<5.0.17
Event History
Jan 31, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-12772?
CVE-2024-12772 has been classified as a high severity Cross Site Scripting vulnerability.
2
How do I fix CVE-2024-12772?
To fix CVE-2024-12772, update the Ninja Tables WordPress plugin to version 5.0.17 or later.
3
What causes CVE-2024-12772?
CVE-2024-12772 is caused by insufficient sanitization and escaping of a parameter during CSV import in the Ninja Tables plugin.
4
Can CVE-2024-12772 be exploited?
Yes, CVE-2024-12772 can be exploited by attackers to execute arbitrary JavaScript in the context of the user's session.
5
Which versions of the Ninja Tables plugin are affected by CVE-2024-12772?
CVE-2024-12772 affects all versions of the Ninja Tables WordPress plugin prior to 5.0.17.