WordPress security by component
wpDataTables – Tables & Table Charts premium
Plugin description
wpDataTables – Tables & Table Charts premium creates sortable, searchable, and responsive tables and charts from data within WordPress.
wpDataTables – Tables & Table Charts premium (wpdatatables) is a WordPress plugin with 20 published CVE records in this archive. The latest tracked vulnerability was published Aug 20, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
wpdatatablesLatest vulnerability
CVE-2026-66597: wpDataTables permits unauthenticated cross-site scripting
wpDataTables <= 6.5.1.4 allows an unauthenticated attacker to supply script-capable input that reaches browser output without adequate neutralization. The CNA vector requires victim interaction and assigns changed scope with low confidentiality, integrity and availability impact. Script executes in the site's origin when a victim interacts with the affected output.
| Safe version |
|
||
|---|---|---|---|
| Aug 20, 2026 |
CVE-2026-66597
wpDataTables permits unauthenticated cross-site scripting
wpDataTables <= 6.5.1.4 allows an unauthenticated attacker to supply script-capable input that reaches browser output without adequate neutralization. The CNA vector requires victim interaction and assigns changed scope with low confidentiality, integrity and availability impact. Script executes in the site's origin when a victim interacts with the affected output.
|
6.5.1.5 |
CVE7.1
NVDPending
|
| Aug 06, 2026 |
CVE-2026-65509
wpDataTables permits unauthenticated cross-site scripting
An unauthenticated visitor can submit attacker-controlled content that wpDataTables 7.5.1 and earlier renders without sufficient output encoding, allowing script execution in a victim's browser under the site's origin.
|
7.5.2 |
CVE7.1
NVDPending
|
| Jul 02, 2026 |
CVE-2026-57672
wpDataTables: Cross-site scripting
wpDataTables is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 6.5.1.1.
|
6.5.1.2 |
CVE7.1
NVDPending
|
| Jun 26, 2026 |
CVE-2026-54825
wpDataTables: SQL injection
wpDataTables is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 7.4.
|
7.4.1 |
CVE9.3
NVDPending
|
| Jun 17, 2026 |
CVE-2026-49080
wpDataTables: SQL injection
wpDataTables is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 7.3.6.
|
7.4 |
CVE9.3
NVDPending
|
| Mar 05, 2026 |
CVE-2026-28039
wpDataTables: Filesystem traversal
wpDataTables is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.5
NVDPending
|
| May 23, 2024 |
CVE-2024-4895
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin: Cross-site scripting
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.7
NVDPending
|
| Mar 13, 2024 |
CVE-2024-0591
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin: Cross-site scripting
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Sep 11, 2023 |
CVE-2023-4314
wpDataTables: Code execution
wpDataTables is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| May 03, 2023 |
CVE-2023-23876
Wpdatatables: Cross-site scripting
Wpdatatables is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| May 20, 2022 |
CVE-2022-29432
Wpdatatables: Cross-site scripting
Wpdatatables is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE3.4
NVD4.8
|
| Apr 04, 2022 |
CVE-2022-25618
Wpdatatables: Cross-site scripting
Wpdatatables is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE3.4
NVD4.8
|
| Apr 12, 2021 |
CVE-2021-24200
wpDataTables – Tables & Table Charts premium: SQL injection
wpDataTables – Tables & Table Charts premium is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD6.5
|
| Apr 12, 2021 |
CVE-2021-24199
wpDataTables – Tables & Table Charts premium: SQL injection
wpDataTables – Tables & Table Charts premium is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD6.5
|
| Apr 12, 2021 |
CVE-2021-24198
wpDataTables – Tables & Table Charts premium: A security weakness
wpDataTables – Tables & Table Charts premium is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD8.1
|
| Apr 12, 2021 |
CVE-2021-24197
wpDataTables – Tables & Table Charts premium: A security weakness
wpDataTables – Tables & Table Charts premium is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD8.1
|
| Feb 08, 2021 |
CVE-2021-26754
Wpdatatables: SQL injection
Wpdatatables is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD9.8
|
| Dec 26, 2019 |
CVE-2019-6012
Wpdatatables: SQL injection
Wpdatatables is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD7.2
|
| Dec 26, 2019 |
CVE-2019-6011
Wpdatatables: Cross-site scripting
Wpdatatables is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Dec 02, 2014 |
CVE-2014-9175
Wpdatatables: SQL injection
Wpdatatables is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD7.5
|