Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.10.46
unknown
[en] The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cleanCache() function in all versions up to, and including, 1.10.45. This makes it possible for authenticated attackers, with Administrator-level access and above, to...
- Affected:
- up to 1.10.46
- Fixed in:
- 1.10.46
- Disclosed:
- Nov 13, 2025
CVE-2025-12089 on NVD →
Data Tables Generator by Supsystic <= 1.10.45 - Authenticated (Admin+) Arbitrary File Deletion
medium
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cleanCache() function in all versions up to, and including, 1.10.45. This makes it possible for authenticated attackers, with Administrator-level access and above, to dele...
- CVSS:
- 6.5
- Affected:
- up to 1.10.45
- Fixed in:
- 1.10.46
- Disclosed:
- Nov 12, 2025
CVE-2025-12089 on NVD →
Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.10.37
unknown
[en] Missing Authorization vulnerability in supsystic.com Data Tables Generator by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Data Tables Generator by Supsystic: from n/a through 1.10.36.
- Affected:
- up to 1.10.37
- Fixed in:
- 1.10.37
- Disclosed:
- Jan 2, 2025
CVE-2024-56253 on NVD →
Data Tables Generator by Supsystic <= 1.10.36 - Missing Authorization
medium
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.10.36. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.10.36
- Fixed in:
- 1.10.37
- Disclosed:
- Dec 30, 2024
CVE-2024-56253 on NVD →
Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.10.32
unknown
[en] Missing Authorization vulnerability in Supsystic Data Tables Generator by Supsystic.This issue affects Data Tables Generator by Supsystic: from n/a through 1.10.31.
- Affected:
- up to 1.10.32
- Fixed in:
- 1.10.32
- Disclosed:
- Apr 26, 2024
CVE-2024-32829 on NVD →
Data Tables Generator by Supsystic <= 1.10.31 - Missing Authorization
medium
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.10.31. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.
- CVSS:
- 4.3
- Affected:
- up to 1.10.31
- Fixed in:
- 1.10.32
- Disclosed:
- Apr 22, 2024
CVE-2024-32829 on NVD →
Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.10.26
unknown
[en] Incorrect Authorization vulnerability in Supsystic Data Tables Generator.This issue affects Data Tables Generator: from n/a through 1.10.25.
- Affected:
- up to 1.10.26
- Fixed in:
- 1.10.26
- Disclosed:
- Apr 17, 2024
CVE-2023-25043 on NVD →
Data Tables Generator by Supsystic <= 1.10.25 - Missing Authorization
medium
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to unauthorized access, modification or loss of data due to the plugin making nonces available to insufficiently privileged users inn the loadDataTablesNonces function in versions up to, and including, 1.10.25. This makes it possible for authenti...
- CVSS:
- 6.3
- Affected:
- up to 1.10.25
- Fixed in:
- 1.10.26
- Disclosed:
- Mar 13, 2023
CVE-2023-25043 on NVD →
Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.10.20
unknown
[en] The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 1.10.20
- Fixed in:
- 1.10.20
- Disclosed:
- Jul 17, 2022
CVE-2022-2114 on NVD →
Data Tables Generator By Supsystic <= 1.10.19 - Cross-Site Scripting
medium
The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
- CVSS:
- 5.5
- Affected:
- up to 1.10.19
- Fixed in:
- 1.10.20
- Disclosed:
- Jun 22, 2022
CVE-2022-2114 on NVD →
Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.10.20
unknown
The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 1.10.20
- Fixed in:
- 1.10.20
- Disclosed:
- Jun 22, 2022
Data Tables Generator by Supsystic <= 1.9.99 - Time-Based Blind SQL Injection
high
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to time-based blind SQL Injection via the ‘data[search][text_like]’ parameter in versions up to, and including, 1.9.99 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This...
- CVSS:
- 8.8
- Affected:
- up to 1.9.99
- Fixed in:
- 1.10.0
- Disclosed:
- Feb 8, 2021
Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.9.97
unknown
Stored Cross-Site Scripting (XSS) vulnerability found by Erik David Martin in WordPress Data Tables Generator by Supsystic plugin (versions <= 1.9.96).
- Affected:
- up to 1.9.97
- Fixed in:
- 1.9.97
- Disclosed:
- Feb 8, 2021
Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.9.97
unknown
SQL injection (SQLi) vulnerability found by Erik David Martin in WordPress Data Tables Generator by Supsystic plugin (versions <= 1.9.96).
- Affected:
- up to 1.9.97
- Fixed in:
- 1.9.97
- Disclosed:
- Feb 8, 2021
Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.10.0
unknown
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to time-based blind SQL Injection via the ‘data[search][text_like]’ parameter in versions up to, and including, 1.9.99 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This...
- Affected:
- up to 1.10.0
- Fixed in:
- 1.10.0
- Disclosed:
- Feb 8, 2021
Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.9.92
unknown
[en] The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS.
- Affected:
- up to 1.9.92
- Fixed in:
- 1.9.92
- Disclosed:
- Apr 23, 2020
CVE-2020-12076 on NVD →
Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.9.92
unknown
[en] The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.
- Affected:
- up to 1.9.92
- Fixed in:
- 1.9.92
- Disclosed:
- Apr 23, 2020
CVE-2020-12075 on NVD →
Data Tables Generator by Supsystic <= 1.9.91 - Cross-Site Request Forgery
high
The Data Tables Generator by Supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS.
- CVSS:
- 8.8
- Affected:
- up to 1.9.91
- Fixed in:
- 1.9.92
- Disclosed:
- Mar 24, 2020
CVE-2020-12076 on NVD →
Data Tables Generator by Supsystic <= 1.9.91 - Missing Authorization on AJAX Actions
medium
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.
- CVSS:
- 6.3
- Affected:
- up to 1.9.91
- Fixed in:
- 1.9.92
- Disclosed:
- Mar 23, 2020
CVE-2020-12075 on NVD →
Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.10.0
unknown
- Affected:
- up to 1.10.0
- Fixed in:
- 1.10.0
Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.10.1
unknown
The "Editor" tab under the "Tables" section is vulnerable to stored XSS. It is possible to store XSS in all input fields as the code does not sanitise any of the user input.
- Affected:
- up to 1.10.1
- Fixed in:
- 1.10.1
Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.9.92
unknown
The Data Tables Generator by Supsystic WordPress plugin was affected by an Authenticated Stored XSS security vulnerability.
- Affected:
- up to 1.9.92
- Fixed in:
- 1.9.92
Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.9.92
unknown
The Data Tables Generator by Supsystic WordPress plugin was affected by a CSRF to Stored XSS, Data Table Creations, Settings Modification security vulnerability.
- Affected:
- up to 1.9.92
- Fixed in:
- 1.9.92
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database