CVE-2025-12089: Data Tables Generator by Supsystic <= 1.10.45 - Authenticated (Admin+) Arbitrary File Deletion
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cleanCache() function in all versions up to, and including, 1.10.45. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12089?
CVE-2025-12089 is classified as a high severity vulnerability due to the potential for arbitrary file deletion.
How do I fix CVE-2025-12089?
To fix CVE-2025-12089, update the Supsystic Data Tables Generator plugin to version 1.10.46 or later.
Who is affected by CVE-2025-12089?
Users of the Supsystic Data Tables Generator plugin for WordPress, specifically those using versions up to and including 1.10.45, are affected by CVE-2025-12089.
What type of attack is possible with CVE-2025-12089?
CVE-2025-12089 allows authenticated attackers to delete arbitrary files from the server.
When was CVE-2025-12089 disclosed?
CVE-2025-12089 was disclosed in October 2025.