Data Tables Generator by Supsystic <= 1.9.91 - Cross-Site Request Forgery

2020-03-24 00:00
Chloe Chamberland

Strategic Overview

Status
Patched in 1.9.92
Affected Version<= 1.9.91
CVSS8.8High
CVECVE-2020-12076
View all Data Tables Generator by Supsystic vulnerabilities

Vulnerability Overview

The Data Tables Generator by Supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS.

Technical Analysis

REMEDIATION: Update to version 1.9.92, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C