CVE-2024-4895: wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 3.4.2.12 - Unauthenticated Stored Cross-Site Scripting via CSV Import
The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CSV import functionality in all versions up to, and including, 3.4.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wpdatatables/wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Pluginto a version that resolves this vulnerability.Fixed in 3.4.2.12 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 3.4.2.12 - Unauthenticated Stored Cross-Site Scripting via CSV Import
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4895?
CVE-2024-4895 has a medium severity rating due to its potential for stored cross-site scripting.
How do I fix CVE-2024-4895?
To fix CVE-2024-4895, upgrade the wpDataTables plugin to version 3.4.2.13 or later.
What versions of wpDataTables are affected by CVE-2024-4895?
CVE-2024-4895 affects all versions of the wpDataTables plugin up to and including version 3.4.2.12.
What type of vulnerability is CVE-2024-4895?
CVE-2024-4895 is a Stored Cross-Site Scripting vulnerability that arises from insufficient input sanitization.
Who can be impacted by CVE-2024-4895?
Users of the wpDataTables plugin with versions up to 3.4.2.12 can be impacted by CVE-2024-4895.