plugin

Wpdatatables Vulnerabilities

46 known security issues reported for the Wpdatatables WordPress plugin. Most recent disclosed Aug 19, 2026.

3 critical 11 high 10 medium

Running Wpdatatables on your site? Check whether your installed version is affected.

Scan your site free

wpDataTables (Premium) <= 6.5.1.4 - Unauthenticated Stored Cross-Site Scripting

high

The wpDataTables (Premium) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.5.1.4. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute...

CVSS:
7.2
Affected:
up to 6.5.1.4
Fixed in:
6.5.1.5
Disclosed:
Aug 19, 2026

CVE-2026-66597 on NVD →

wpDataTables (Premium) <= 7.5.1 - Unauthenticated Stored Cross-Site Scripting

high

The wpDataTables (Premium) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user...

CVSS:
7.2
Affected:
up to 7.5.1
Fixed in:
7.5.2
Disclosed:
Jul 28, 2026

CVE-2026-65509 on NVD →

wpDataTables (Premium) <= 6.5.1.1 - Unauthenticated Stored Cross-Site Scripting

high

The wpDataTables (Premium) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.5.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a us...

CVSS:
7.2
Affected:
up to 6.5.1.1
Fixed in:
6.5.1.2
Disclosed:
Jun 30, 2026

CVE-2026-57672 on NVD →

wpDataTables (Premium) <= 7.4 - Unauthenticated SQL Injection

high

The wpDataTables (Premium) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL que...

CVSS:
7.5
Affected:
up to 7.4
Fixed in:
7.4.1
Disclosed:
Jun 17, 2026

CVE-2026-54825 on NVD →

wpDataTables (Premium) <= 7.3.6 - Unauthenticated SQL Injection

high

The wpDataTables (Premium) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL q...

CVSS:
7.5
Affected:
up to 7.3.6
Fixed in:
7.4
Disclosed:
Jun 8, 2026

CVE-2026-49080 on NVD →

wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 6.5.0.4 - Unauthenticated Stored Cross-Site Scripting via CSV/Excel Data Import

medium

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.5.0.4. This is due to insufficient input sanitization and output escaping in the prepareCellOutput() method of the LinkWDTColumn, ImageW...

CVSS:
4.7
Affected:
up to 6.5.0.4
Fixed in:
6.5.0.5
Disclosed:
Apr 20, 2026

CVE-2026-5721 on NVD →

wpDataTables (Premium) <= 6.5.0.1 - Unauthenticated Local File Inclusion

high

The wpDataTables (Premium) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.5.0.1. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass ac...

CVSS:
8.1
Affected:
up to 6.5.0.1
Fixed in:
6.5.0.2
Disclosed:
Mar 3, 2026

CVE-2026-28039 on NVD →

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 6.4

unknown

[en] The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the wdt_ajax_actions.php file in all versions up to, and including, 6.3.2. This makes it possible for unauthenticated att...

Affected:
up to 6.4
Fixed in:
6.4
Disclosed:
Jun 1, 2024

CVE-2024-3821 on NVD →

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 6.3.2

unknown

[en] The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to SQL Injection via the 'id_key' parameter of the wdt_delete_table_row AJAX action in all versions up to, and including, 6.3.1 due to insufficient escaping on the user supplied parameter and lack of su...

Affected:
up to 6.3.2
Fixed in:
6.3.2
Disclosed:
Jun 1, 2024

CVE-2024-3820 on NVD →

wpDataTables - Tables & Table Charts (Premium) <= 6.3.1 - Unauthenticated SQL Injection

critical

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to SQL Injection via the 'id_key' parameter of the wdt_delete_table_row AJAX action in all versions up to, and including, 6.3.1 due to insufficient escaping on the user supplied parameter and lack of suffici...

CVSS:
10
Affected:
up to 6.3.1
Fixed in:
6.3.2
Disclosed:
May 31, 2024

CVE-2024-3820 on NVD →

wpDataTables - Tables & Table Charts (Premium) <= 6.3.2 - Missing Authorization to DataTable Access & Modification

high

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the wdt_ajax_actions.php file in all versions up to, and including, 6.3.2. This makes it possible for unauthenticated attacker...

CVSS:
7.3
Affected:
up to 6.3.2
Fixed in:
6.4
Disclosed:
May 31, 2024

CVE-2024-3821 on NVD →

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 3.4.2.14

unknown

[en] The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CSV import functionality in all versions up to, and including, 3.4.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unau...

Affected:
up to 3.4.2.14
Fixed in:
3.4.2.14
Disclosed:
May 23, 2024

CVE-2024-4895 on NVD →

wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 3.4.2.12 - Unauthenticated Stored Cross-Site Scripting via CSV Import

medium

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CSV import functionality in all versions up to, and including, 3.4.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthent...

CVSS:
4.7
Affected:
up to 3.4.2.12
Fixed in:
3.4.2.14
Disclosed:
May 22, 2024

CVE-2024-4895 on NVD →

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 3.4.2.5

unknown

[en] The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'A' parameter in all versions up to, and including, 3.4.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...

Affected:
up to 3.4.2.5
Fixed in:
3.4.2.5
Disclosed:
Mar 13, 2024

CVE-2024-0591 on NVD →

wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 3.4.2.2 - Reflected Cross-Site Scripting.

medium

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'A' parameter in all versions up to, and including, 3.4.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated at...

CVSS:
6.1
Affected:
up to 3.4.2.4
Fixed in:
3.4.2.5
Disclosed:
Feb 20, 2024

CVE-2024-0591 on NVD →

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 2.1.66

unknown

[en] The wpDataTables WordPress plugin before 2.1.66 does not validate the "Serialized PHP array" input data before deserializing the data. This allows admins to deserialize arbitrary data which may lead to remote code execution if a suitable gadget chain is present on the server. This is impactful in environments wher...

Affected:
up to 2.1.66
Fixed in:
2.1.66
Disclosed:
Sep 11, 2023

CVE-2023-4314 on NVD →

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 2.1.66

unknown

Update the WordPress wpDataTables plugin to the latest available version (at least 2.1.66). WordFence discovered and reported this PHP Object Injection vulnerability in WordPress wpDataTables Plugin. This could allow a malicious actor to execute code injection, SQL injection, path traversal, denial of service, and more...

Affected:
up to 2.1.66
Fixed in:
2.1.66
Disclosed:
Aug 18, 2023

wpDataTables - Tables & Table Charts <= 2.1.65 - Authenticated(Administrator+) PHP Object Injection

medium

The wpDataTables - Tables & Table Charts plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.65 via deserialization of untrusted input in multiple functions. This allows authenticated attackers with administrator capabilities to inject a PHP Object. The additional presence o...

CVSS:
6.6
Affected:
up to 2.1.66
Fixed in:
2.1.66
Disclosed:
Aug 16, 2023

CVE-2023-4314 on NVD →

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 2.1.66

unknown

The wpDataTables - Tables & Table Charts plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.65 via deserialization of untrusted input in multiple functions. This allows authenticated attackers with administrator capabilities to inject a PHP Object. The additional presence o...

Affected:
up to 2.1.66
Fixed in:
2.1.66
Disclosed:
Aug 16, 2023

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 2.1.50

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TMS-Plugins wpDataTables plugin <= 2.1.49 versions.

Affected:
up to 2.1.50
Fixed in:
2.1.50
Disclosed:
May 3, 2023

CVE-2023-23876 on NVD →

wpDataTables <= 2.1.49 - Authenticated (Contributor+) Stored Cross Site Scripting

medium

The wpDataTables plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.49 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pag...

CVSS:
6.4
Affected:
up to 2.1.49
Fixed in:
2.1.50
Disclosed:
Feb 20, 2023

CVE-2023-23876 on NVD →

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 2.1.28

unknown

[en] Multiple Authenticated (administrator or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in TMS-Plugins wpDataTables plugin <= 2.1.27 on WordPress via &data-link-text, &data-link-url, &data, &data-shortcode, &data-star-num vulnerable parameters.

Affected:
up to 2.1.28
Fixed in:
2.1.28
Disclosed:
May 20, 2022

CVE-2022-29432 on NVD →

wpDataTables <= 2.1.27 - Authenticated Cross-Site Scripting

medium

Multiple Authenticated (administrator or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in TMS-Plugins wpDataTables plugin <= 2.1.27 on WordPress via &data-link-text, &data-link-url, &data, &data-shortcode, &data-star-num vulnerable parameters.

CVSS:
5.5
Affected:
up to 2.1.27
Fixed in:
2.1.28
Disclosed:
May 6, 2022

CVE-2022-29432 on NVD →

wpDataTables – WordPress Tables & Table Charts Plugin <= 2.1.27 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The wpDataTables plugin <= 2.1.27 is vulnerable to authenticated (admin+) Stored Cross-Site Scripting

CVSS:
5.5
Affected:
up to 2.1.27
Fixed in:
2.1.28
Disclosed:
Apr 4, 2022

CVE-2022-25618 on NVD →

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 2.1.28

unknown

[en] Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpDataTables (WordPress plugin) versions <= 2.1.27

Affected:
up to 2.1.28
Fixed in:
2.1.28
Disclosed:
Apr 4, 2022

CVE-2022-25618 on NVD →

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 3.4.2

unknown

[en] The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to delete the data of another user that are present in the same table through id_key and id_val...

Affected:
up to 3.4.2
Fixed in:
3.4.2
Disclosed:
Apr 12, 2021

CVE-2021-24198 on NVD →

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 3.4.2

unknown

[en] The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin-ajax.php?action=get_wdtable&table_id=1, on the 'length' HTTP POST parameter. This allows an at...

Affected:
up to 3.4.2
Fixed in:
3.4.2
Disclosed:
Apr 12, 2021

CVE-2021-24200 on NVD →

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 3.4.2

unknown

[en] The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to access the data of another user that are present in the same table by taking over the user pe...

Affected:
up to 3.4.2
Fixed in:
3.4.2
Disclosed:
Apr 12, 2021

CVE-2021-24197 on NVD →

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 3.4.2

unknown

[en] The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin-ajax.php?action=get_wdtable&table_id=1, on the 'start' HTTP POST parameter. This allows an att...

Affected:
up to 3.4.2
Fixed in:
3.4.2
Disclosed:
Apr 12, 2021

CVE-2021-24199 on NVD →

wpDataTables (Premium) <= 3.4.1 - Improper Access Control leading to Table Permission Takeover

high

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to access the data of another user that are present in the same table by taking over the user permiss...

CVSS:
8.1
Affected:
up to 3.4.2
Fixed in:
3.4.2
Disclosed:
Mar 16, 2021

CVE-2021-24197 on NVD →

wpDataTables (Premium) <= 3.4.1 - Improper Access Control leading to Table Data Deletion

high

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to delete the data of another user that are present in the same table through id_key and id_val param...

CVSS:
8.1
Affected:
up to 3.4.2
Fixed in:
3.4.2
Disclosed:
Mar 16, 2021

CVE-2021-24198 on NVD →

wpDataTables (Premium) <= 3.4.1 - Blind SQL Injection via length Parameter

medium

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin-ajax.php?action=get_wdtable&table_id=1, on the 'length' HTTP POST parameter. This allows an attacke...

CVSS:
6.5
Affected:
up to 3.4.2
Fixed in:
3.4.2
Disclosed:
Mar 16, 2021

CVE-2021-24200 on NVD →

wpDataTables (Premium) <= 3.4.1 - Blind SQL Injection via start Parameter

medium

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin-ajax.php?action=get_wdtable&table_id=1, on the 'start' HTTP POST parameter. This allows an attacker...

CVSS:
6.5
Affected:
up to 3.4.2
Fixed in:
3.4.2
Disclosed:
Mar 16, 2021

CVE-2021-24199 on NVD →

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 3.4.1

unknown

[en] wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order[0][dir] SQL injection.

Affected:
up to 3.4.1
Fixed in:
3.4.1
Disclosed:
Feb 7, 2021

CVE-2021-26754 on NVD →

wpDataTables (Premium) <= 3.4 - SQL Injection

high

wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order[0][dir] SQL injection. Please note that this only affects the premium version of the plugin which shares the same slug as the free version.

CVSS:
8.8
Affected:
up to 3.4
Fixed in:
3.4.1
Disclosed:
Feb 2, 2021

CVE-2021-26754 on NVD →

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 2.0.12

unknown

[en] SQL injection vulnerability in the wpDataTables Lite Version 2.0.11 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

Affected:
up to 2.0.12
Fixed in:
2.0.12
Disclosed:
Dec 26, 2019

CVE-2019-6012 on NVD →

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 2.0.12

unknown

[en] Cross-site scripting vulnerability in wpDataTables Lite Version 2.0.11 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected:
up to 2.0.12
Fixed in:
2.0.12
Disclosed:
Dec 26, 2019

CVE-2019-6011 on NVD →

wpDataTables Lite plugin <= 2.0.11 - SQL injection

high

SQL injection vulnerability in the wpDataTables Lite Version 2.0.11 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS:
7.2
Affected:
up to 2.0.11
Fixed in:
2.0.12
Disclosed:
Oct 16, 2019

CVE-2019-6012 on NVD →

wpDataTables Lite plugin <= 2.0.11 - Cross-Site Scripting

medium

Cross-site scripting vulnerability in wpDataTables Lite Version 2.0.11 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:
6.1
Affected:
up to 2.0.11
Fixed in:
2.0.12
Disclosed:
Oct 16, 2019

CVE-2019-6011 on NVD →

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 1.2.2

unknown

WordPress wpDataTables Lite plugin is prone to a Cross-Site scripting (XSS) vulnerability. Some of the plugin's settings are not escaped when they are retrieved from the database. Update the plugin.

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Dec 12, 2016

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 1.5.4

unknown

[en] SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the table_id parameter in a get_wdtable action to wp-admin/admin-ajax.php.

Affected:
up to 1.5.4
Fixed in:
1.5.4
Disclosed:
Dec 2, 2014

CVE-2014-9175 on NVD →

wpDataTables <= 1.5.3 - Arbitrary File Upload

critical

The wpDataTables plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the (1) wdt_upload_file function and in the (2) lib/upload/UploadHandler.php file in versions before 1.5.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected...

CVSS:
9.8
Affected:
up to 1.5.4
Fixed in:
1.5.4
Disclosed:
Nov 25, 2014

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 1.5.4

unknown

The wpDataTables plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the (1) wdt_upload_file function and in the (2) lib/upload/UploadHandler.php file in versions before 1.5.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected...

Affected:
up to 1.5.4
Fixed in:
1.5.4
Disclosed:
Nov 25, 2014

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 1.5.4

unknown

There are "wpdatables.php", that is always available without wpdatatables edit permission, and "UploadHandler.php", that allows to upload any type of file. Update the plugin.

Affected:
up to 1.5.4
Fixed in:
1.5.4
Disclosed:
Nov 24, 2014

wpDataTables (Premium) <= 1.5.3 - SQL Injection

critical

SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the table_id parameter in a get_wdtable action to wp-admin/admin-ajax.php.

CVSS:
9.8
Affected:
up to 1.5.3
Fixed in:
1.5.4
Disclosed:
Nov 23, 2014

CVE-2014-9175 on NVD →

wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 1.5.4

unknown

The wpDataTables &ndash; Tables &amp; Table Charts WordPress plugin was affected by an Unauthenticated Shell Upload security vulnerability.

Affected:
up to 1.5.4
Fixed in:
1.5.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database