← WordPress Vulnerabilities
WordPress security by component

wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin

wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Apr 20, 2026; the highest CVE/CNA score is 10.

Plugin slug: wpdatatables-wordpress-data-table-dynamic-tables-table-charts-plugin

CVE-2026-5721: wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin: Cross-site scripting

wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 6.5.0.4.

PublishedApr 20, 2026
Known safe version> 6.5.0.4
Safe version
Apr 20, 2026 CVE-2026-5721
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin: Cross-site scripting
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 6.5.0.4.
> 6.5.0.4
CVE4.7
NVDPending
Jun 01, 2024 CVE-2024-3821
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin: A security weakness
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.3
NVDPending
Jun 01, 2024 CVE-2024-3820
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin: SQL injection
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE10.0
NVDPending