plugin

Data Tables Generator By Supsystic Vulnerabilities

23 known security issues reported for the Data Tables Generator By Supsystic WordPress plugin. Most recent disclosed Nov 13, 2025.

2 high 6 medium

Running Data Tables Generator By Supsystic on your site? Check whether your installed version is affected.

Scan your site free

Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.10.46

unknown

[en] The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cleanCache() function in all versions up to, and including, 1.10.45. This makes it possible for authenticated attackers, with Administrator-level access and above, to...

Affected:
up to 1.10.46
Fixed in:
1.10.46
Disclosed:
Nov 13, 2025

CVE-2025-12089 on NVD →

Data Tables Generator by Supsystic <= 1.10.45 - Authenticated (Admin+) Arbitrary File Deletion

medium

The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cleanCache() function in all versions up to, and including, 1.10.45. This makes it possible for authenticated attackers, with Administrator-level access and above, to dele...

CVSS:
6.5
Affected:
up to 1.10.45
Fixed in:
1.10.46
Disclosed:
Nov 12, 2025

CVE-2025-12089 on NVD →

Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.10.37

unknown

[en] Missing Authorization vulnerability in supsystic.com Data Tables Generator by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Data Tables Generator by Supsystic: from n/a through 1.10.36.

Affected:
up to 1.10.37
Fixed in:
1.10.37
Disclosed:
Jan 2, 2025

CVE-2024-56253 on NVD →

Data Tables Generator by Supsystic <= 1.10.36 - Missing Authorization

medium

The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.10.36. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.10.36
Fixed in:
1.10.37
Disclosed:
Dec 30, 2024

CVE-2024-56253 on NVD →

Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.10.32

unknown

[en] Missing Authorization vulnerability in Supsystic Data Tables Generator by Supsystic.This issue affects Data Tables Generator by Supsystic: from n/a through 1.10.31.

Affected:
up to 1.10.32
Fixed in:
1.10.32
Disclosed:
Apr 26, 2024

CVE-2024-32829 on NVD →

Data Tables Generator by Supsystic <= 1.10.31 - Missing Authorization

medium

The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.10.31. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.

CVSS:
4.3
Affected:
up to 1.10.31
Fixed in:
1.10.32
Disclosed:
Apr 22, 2024

CVE-2024-32829 on NVD →

Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.10.26

unknown

[en] Incorrect Authorization vulnerability in Supsystic Data Tables Generator.This issue affects Data Tables Generator: from n/a through 1.10.25.

Affected:
up to 1.10.26
Fixed in:
1.10.26
Disclosed:
Apr 17, 2024

CVE-2023-25043 on NVD →

Data Tables Generator by Supsystic <= 1.10.25 - Missing Authorization

medium

The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to unauthorized access, modification or loss of data due to the plugin making nonces available to insufficiently privileged users inn the loadDataTablesNonces function in versions up to, and including, 1.10.25. This makes it possible for authenti...

CVSS:
6.3
Affected:
up to 1.10.25
Fixed in:
1.10.26
Disclosed:
Mar 13, 2023

CVE-2023-25043 on NVD →

Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.10.20

unknown

[en] The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 1.10.20
Fixed in:
1.10.20
Disclosed:
Jul 17, 2022

CVE-2022-2114 on NVD →

Data Tables Generator By Supsystic <= 1.10.19 - Cross-Site Scripting

medium

The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS:
5.5
Affected:
up to 1.10.19
Fixed in:
1.10.20
Disclosed:
Jun 22, 2022

CVE-2022-2114 on NVD →

Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.10.20

unknown

The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 1.10.20
Fixed in:
1.10.20
Disclosed:
Jun 22, 2022

Data Tables Generator by Supsystic <= 1.9.99 - Time-Based Blind SQL Injection

high

The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to time-based blind SQL Injection via the ‘data[search][text_like]’ parameter in versions up to, and including, 1.9.99 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This...

CVSS:
8.8
Affected:
up to 1.9.99
Fixed in:
1.10.0
Disclosed:
Feb 8, 2021

Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.9.97

unknown

Stored Cross-Site Scripting (XSS) vulnerability found by Erik David Martin in WordPress Data Tables Generator by Supsystic plugin (versions <= 1.9.96).

Affected:
up to 1.9.97
Fixed in:
1.9.97
Disclosed:
Feb 8, 2021

Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.9.97

unknown

SQL injection (SQLi) vulnerability found by Erik David Martin in WordPress Data Tables Generator by Supsystic plugin (versions <= 1.9.96).

Affected:
up to 1.9.97
Fixed in:
1.9.97
Disclosed:
Feb 8, 2021

Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.10.0

unknown

The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to time-based blind SQL Injection via the ‘data[search][text_like]’ parameter in versions up to, and including, 1.9.99 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This...

Affected:
up to 1.10.0
Fixed in:
1.10.0
Disclosed:
Feb 8, 2021

Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.9.92

unknown

[en] The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS.

Affected:
up to 1.9.92
Fixed in:
1.9.92
Disclosed:
Apr 23, 2020

CVE-2020-12076 on NVD →

Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.9.92

unknown

[en] The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.

Affected:
up to 1.9.92
Fixed in:
1.9.92
Disclosed:
Apr 23, 2020

CVE-2020-12075 on NVD →

Data Tables Generator by Supsystic <= 1.9.91 - Cross-Site Request Forgery

high

The Data Tables Generator by Supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS.

CVSS:
8.8
Affected:
up to 1.9.91
Fixed in:
1.9.92
Disclosed:
Mar 24, 2020

CVE-2020-12076 on NVD →

Data Tables Generator by Supsystic <= 1.9.91 - Missing Authorization on AJAX Actions

medium

The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.

CVSS:
6.3
Affected:
up to 1.9.91
Fixed in:
1.9.92
Disclosed:
Mar 23, 2020

CVE-2020-12075 on NVD →

Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.10.0

unknown
Affected:
up to 1.10.0
Fixed in:
1.10.0

Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.10.1

unknown

The &quot;Editor&quot; tab under the &quot;Tables&quot; section is vulnerable to stored XSS. It is possible to store XSS in all input fields as the code does not sanitise any of the user input.

Affected:
up to 1.10.1
Fixed in:
1.10.1

Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.9.92

unknown

The Data Tables Generator by Supsystic WordPress plugin was affected by an Authenticated Stored XSS security vulnerability.

Affected:
up to 1.9.92
Fixed in:
1.9.92

Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.9.92

unknown

The Data Tables Generator by Supsystic WordPress plugin was affected by a CSRF to Stored XSS, Data Table Creations, Settings Modification security vulnerability.

Affected:
up to 1.9.92
Fixed in:
1.9.92

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database