Extension WordPress
Vulnérabilités wpDataTables (Premium)
Cette page rassemble les failles publiées pour wpDataTables (Premium), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de wpDataTables (Premium)
22 fiches
wpDataTables (Premium) <= 6.5.1.1 – Unauthenticated Stored Cross-Site Scripting
The wpDataTables (Premium) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.5.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-6.5.1.1
6.5.1.2
30/06/2026
wpDataTables (Premium) <= 7.4 – Unauthenticated SQL Injection
The wpDataTables (Premium) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
*-7.4
7.4.1
17/06/2026
wpDataTables (Premium) <= 7.3.6 – Unauthenticated SQL Injection
The wpDataTables (Premium) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
*-7.3.6
7.4
08/06/2026
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 6.5.0.4 – Unauthenticated Stored Cross-Site Scripting via CSV/Excel Data Import
The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.5.0.4. This is due to insufficient input sanitization and output…
*-6.5.0.4
6.5.0.5
20/04/2026
wpDataTables (Premium) <= 6.5.0.1 – Unauthenticated Local File Inclusion
The wpDataTables (Premium) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.5.0.1. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution…
*-6.5.0.1
6.5.0.2
03/03/2026
wpDataTables – Tables & Table Charts (Premium) <= 6.3.1 – Unauthenticated SQL Injection
The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to SQL Injection via the 'id_key' parameter of the wdt_delete_table_row AJAX action in all versions up to, and including, 6.3.1 due…
*-6.3.1
6.3.2
31/05/2024
wpDataTables – Tables & Table Charts (Premium) <= 6.3.2 – Missing Authorization to DataTable Access & Modification
The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the wdt_ajax_actions.php file in all versions up to,…
*-6.3.2
6.4
31/05/2024
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 3.4.2.12 – Unauthenticated Stored Cross-Site Scripting via CSV Import
The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CSV import functionality in all versions up to, and including, 3.4.2.12 due to insufficient input…
*-3.4.2.12
3.4.2.14
22/05/2024
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 3.4.2.2 – Reflected Cross-Site Scripting.
The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'A' parameter in all versions up to, and including, 3.4.2.2 due to insufficient input sanitization…
*-3.4.2.4
3.4.2.5
20/02/2024
wpDataTables – Tables & Table Charts <= 2.1.65 – Authenticated(Administrator+) PHP Object Injection
The wpDataTables – Tables & Table Charts plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.65 via deserialization of untrusted input in multiple functions. This allows authenticated attackers with administrator capabilities…
[*, 2.1.66)
2.1.66
16/08/2023
wpDataTables <= 2.1.49 – Authenticated (Contributor+) Stored Cross Site Scripting
The wpDataTables plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.49 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above,…
*-2.1.49
2.1.50
20/02/2023
wpDataTables <= 2.1.27 – Authenticated Cross-Site Scripting
Multiple Authenticated (administrator or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in TMS-Plugins wpDataTables plugin
*-2.1.27
2.1.28
06/05/2022
wpDataTables – WordPress Tables & Table Charts Plugin <= 2.1.27 – Authenticated (Admin+) Stored Cross-Site Scripting
The wpDataTables plugin
*-2.1.27
2.1.28
04/04/2022
wpDataTables (Premium) <= 3.4.1 – Blind SQL Injection via start Parameter
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin-ajax.php?action=get_wdtable&table_id=1, on the 'start' HTTP POST…
[*, 3.4.2)
3.4.2
16/03/2021
wpDataTables (Premium) <= 3.4.1 – Improper Access Control leading to Table Data Deletion
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to delete the data…
[*, 3.4.2)
3.4.2
16/03/2021
wpDataTables (Premium) <= 3.4.1 – Blind SQL Injection via length Parameter
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin-ajax.php?action=get_wdtable&table_id=1, on the 'length' HTTP POST…
[*, 3.4.2)
3.4.2
16/03/2021
wpDataTables (Premium) <= 3.4.1 – Improper Access Control leading to Table Permission Takeover
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to access the data…
[*, 3.4.2)
3.4.2
16/03/2021
wpDataTables (Premium) <= 3.4 – SQL Injection
wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order[0][dir] SQL injection. Please note that this only affects the premium version of the plugin which shares the same slug as the free version.
*-3.4
3.4.1
02/02/2021
wpDataTables Lite plugin <= 2.0.11 – Cross-Site Scripting
Cross-site scripting vulnerability in wpDataTables Lite Version 2.0.11 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
*-2.0.11
2.0.12
16/10/2019
wpDataTables Lite plugin <= 2.0.11 – SQL injection
SQL injection vulnerability in the wpDataTables Lite Version 2.0.11 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
*-2.0.11
2.0.12
16/10/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.