Ninja Tables – Easy Data Table Builder <= 5.2.9 - Unauthenticated Stored Cross-Site Scripting
high
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.2.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute...
- CVSS:
- 7.2
- Affected:
- up to 5.2.9
- Fixed in:
- 5.2.10
- Disclosed:
- Aug 4, 2026
CVE-2026-61964 on NVD →
Ninja Tables – Easy Data Table Builder <= 5.2.10 - Unauthenticated Information Exposure
medium
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.10. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 5.2.10
- Fixed in:
- 5.2.11
- Disclosed:
- Jul 22, 2026
CVE-2026-65474 on NVD →
Ninja Tables <= 5.2.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Table Creation
medium
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation due to missing authorization checks on the `createFluentCartTable` function in all versions up to, and including, 5.2.6. This makes it possible for authenticated attackers, with Subscriber-level access...
- CVSS:
- 4.3
- Affected:
- up to 5.2.6
- Fixed in:
- 5.2.7
- Disclosed:
- May 5, 2026
CVE-2026-2306 on NVD →
Ninja Tables – Easy Data Table Builder [ninja-tables] <= 5.2.5 (unfixed)
unknown
[en] Insertion of Sensitive Information Into Sent Data vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allows Retrieve Embedded Sensitive Data.This issue affects Ninja Tables: from n/a through <= 5.2.5.
- Affected:
- up to 5.2.5
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25008 on NVD →
Ninja Tables – Easy Data Table Builder <= 5.2.5 - Authenticated (Contributor+) Information Exposure
medium
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 5.2.5
- Fixed in:
- 5.2.6
- Disclosed:
- Jan 18, 2026
CVE-2026-25008 on NVD →
Ninja Tables <= 5.2.4 - Authenticated (Contributor+) SQL Injection
medium
The Ninja Tables plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and abo...
- CVSS:
- 6.5
- Affected:
- up to 5.2.4
- Fixed in:
- 5.2.5
- Disclosed:
- Jan 7, 2026
CVE-2025-69351 on NVD →
Ninja Tables – Easy Data Table Builder [ninja-tables] <= 5.2.4 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allows Blind SQL Injection.This issue affects Ninja Tables: from n/a through <= 5.2.4.
- Affected:
- up to 5.2.4
- Fix:
- No patched version reported
- Disclosed:
- Jan 6, 2026
CVE-2025-69351 on NVD →
Ninja Tables <= 5.2.3 - Authenticated (Administrator+) SQL Injection
medium
The Ninja Tables plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and a...
- CVSS:
- 4.9
- Affected:
- up to 5.2.3
- Fixed in:
- 5.2.4
- Disclosed:
- Dec 15, 2025
CVE-2025-67519 on NVD →
Ninja Tables – Easy Data Table Builder [ninja-tables] <= 5.2.3 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allows SQL Injection.This issue affects Ninja Tables: from n/a through <= 5.2.3.
- Affected:
- up to 5.2.3
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-67519 on NVD →
Ninja Tables – Easy Data Table Builder <= 5.0.18 - Unauthenticated Server-Side Request Forgery
high
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.18 via the args[url] parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and...
- CVSS:
- 7.2
- Affected:
- up to 5.0.18
- Fixed in:
- 5.0.19
- Disclosed:
- Jun 26, 2025
CVE-2025-2940 on NVD →
Ninja Tables – Easy Data Table Builder <= 5.0.18 - Unauthenticated PHP Object Injection to Limited Remote Code Execution
medium
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presen...
- CVSS:
- 5.6
- Affected:
- up to 5.0.18
- Fixed in:
- 5.0.19
- Disclosed:
- Jun 2, 2025
CVE-2025-2939 on NVD →
Ninja Tables – Easy Data Table Builder [ninja-tables] < 5.0.17
unknown
[en] The Ninja Tables WordPress plugin before 5.0.17 does not sanitize and escape a parameter before outputting it back in the page when importing a CSV, leading to a Cross Site Scripting vulnerability.
- Affected:
- up to 5.0.17
- Fixed in:
- 5.0.17
- Disclosed:
- Jan 31, 2025
CVE-2024-12772 on NVD →
Ninja Tables – Easy Data Table <= 5.0.16 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a CSV import in all versions up to, and including, 5.0.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions...
- CVSS:
- 4.4
- Affected:
- up to 5.0.16
- Fixed in:
- 5.0.17
- Disclosed:
- Jan 9, 2025
CVE-2024-12772 on NVD →
Ninja Tables – Easy Data Table Builder [ninja-tables] < 5.0.13
unknown
[en] The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access...
- Affected:
- up to 5.0.13
- Fixed in:
- 5.0.13
- Disclosed:
- Aug 27, 2024
CVE-2024-7304 on NVD →
Ninja Tables – Easiest Data Table Builder <= 5.0.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
medium
The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and a...
- CVSS:
- 6.4
- Affected:
- up to 5.0.12
- Fixed in:
- 5.0.13
- Disclosed:
- Aug 26, 2024
CVE-2024-7304 on NVD →
Ninja Tables – Easy Data Table Builder [ninja-tables] < 5.0.6
unknown
[en] Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.5.
- Affected:
- up to 5.0.6
- Fixed in:
- 5.0.6
- Disclosed:
- Jun 14, 2024
CVE-2024-23504 on NVD →
Ninja Tables – Easy Data Table Builder [ninja-tables] < 5.0.7
unknown
[en] Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.6.
- Affected:
- up to 5.0.7
- Fixed in:
- 5.0.7
- Disclosed:
- Jun 11, 2024
CVE-2024-23503 on NVD →
Ninja Tables – Easy Data Table Builder [ninja-tables] < 5.0.10
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.9.
- Affected:
- up to 5.0.10
- Fixed in:
- 5.0.10
- Disclosed:
- Jun 3, 2024
CVE-2024-35635 on NVD →
Ninja Tables – Easiest Data Table Builder <= 5.0.9 - Authenticated (Admin+) Server-Side Request Forgery
medium
The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.9. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web...
- CVSS:
- 5.5
- Affected:
- up to 5.0.9
- Fixed in:
- 5.0.10
- Disclosed:
- May 30, 2024
CVE-2024-35635 on NVD →
Ninja Tables <= 5.0.5 - Missing Authorization
medium
The Ninja Tables plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the defaultExport() and dragAndDropExport() functions in versions up to, and including, 5.0.5. This makes it possible for unauthenticated attackers to export table data.
- CVSS:
- 5.3
- Affected:
- up to 5.0.5
- Fixed in:
- 5.0.6
- Disclosed:
- Jan 19, 2024
CVE-2024-23504 on NVD →
Ninja Tables – Easy Data Table Builder [ninja-tables] <= 5.0.5
unknown
Incomplete patch.
emad discovered and reported this Broken Access Control vulnerability in WordPress Ninja Tables Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged ac...
- Affected:
- up to 5.0.5
- Fixed in:
- 5.0.5
- Disclosed:
- Jan 19, 2024
Ninja Tables – Easy Data Table Builder [ninja-tables] < 4.3.5
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in WPManageNinja LLC Ninja Tables – Best Data Table Plugin for WordPress plugin <= 4.3.4 versions.
- Affected:
- up to 4.3.5
- Fixed in:
- 4.3.5
- Disclosed:
- May 25, 2023
CVE-2022-47136 on NVD →
Ninja Tables – Easy Data Table Builder [ninja-tables] < 4.3.5
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPManageNinja LLC Ninja Tables plugin <= 4.3.4 versions.
- Affected:
- up to 4.3.5
- Fixed in:
- 4.3.5
- Disclosed:
- May 10, 2023
CVE-2022-47137 on NVD →
Ninja Tables <= 4.3.4 - Cross-Site Request Forgery
medium
The Ninja Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.4. This is due to missing or incorrect nonce validation on the remindMeLater function. This makes it possible for unauthenticated attackers to dismiss an admin notice via a forged request granted they...
- CVSS:
- 4.3
- Affected:
- up to 4.3.4
- Fixed in:
- 4.3.5
- Disclosed:
- Apr 20, 2023
CVE-2022-47136 on NVD →
Ninja Tables – Easy Data Table Builder [ninja-tables] < 4.3.5
unknown
The Ninja Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.4. This is due to missing or incorrect nonce validation on the remindMeLater function. This makes it possible for unauthenticated attackers to dismiss an admin notice via a forged request granted they...
- Affected:
- up to 4.3.5
- Fixed in:
- 4.3.5
- Disclosed:
- Apr 20, 2023
Ninja Tables <= 4.3.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings
medium
The Ninja Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to, and including, 4.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrar...
- CVSS:
- 4.4
- Affected:
- up to 4.3.4
- Fixed in:
- 4.3.5
- Disclosed:
- Apr 19, 2023
CVE-2022-47137 on NVD →
Ninja Tables – Easy Data Table Builder [ninja-tables] < 4.1.8
unknown
[en] The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- Affected:
- up to 4.1.8
- Fixed in:
- 4.1.8
- Disclosed:
- Feb 1, 2022
CVE-2021-24900 on NVD →
Ninja Tables <= 4.1.7 - Admin+ Stored Cross-Site Cross-Site Scripting
medium
The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- CVSS:
- 4.8
- Affected:
- up to 4.1.7
- Fixed in:
- 4.1.8
- Disclosed:
- Oct 25, 2021
CVE-2021-24900 on NVD →
Ninja Tables – Easy Data Table Builder [ninja-tables] < 5.0.19
unknown
- Affected:
- up to 5.0.19
- Fixed in:
- 5.0.19
CVE-2025-2939 on NVD →
Ninja Tables – Easy Data Table Builder [ninja-tables] < 5.0.19
unknown
- Affected:
- up to 5.0.19
- Fixed in:
- 5.0.19
CVE-2025-2940 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database