cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches fordata-tables-generator-by-supsystic data-tables-generator-by-supsystic

Direction: ascending
Jun 07, 2024

Data Tables Generator by Supsystic # CVE-2022-2114

CVE, Research URL

CVE-2022-2114

Date
Jul 17, 2022
Research Description
The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
max 1.10.20.
Status
vulnerable

Data Tables Generator by Supsystic # CVE-2020-12075

CVE, Research URL

CVE-2020-12075

Date
Apr 23, 2020
Research Description
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.
Affected versions
max 1.9.92.
Status
vulnerable

Data Tables Generator by Supsystic # CVE-2020-12076

CVE, Research URL

CVE-2020-12076

Date
Apr 23, 2020
Research Description
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS.
Affected versions
max 1.9.92.
Status
vulnerable

Data Tables Generator by Supsystic # CVE-2024-32829

CVE, Research URL

CVE-2024-32829

Date
Apr 26, 2024
Research Description
Missing Authorization vulnerability in Supsystic Data Tables Generator by Supsystic.This issue affects Data Tables Generator by Supsystic: from n/a through 1.10.31.
Affected versions
max 1.10.32.
Status
vulnerable

Data Tables Generator by Supsystic # CVE-2023-25043

CVE, Research URL

CVE-2023-25043

Date
Apr 17, 2024
Research Description
Incorrect Authorization vulnerability in Supsystic Data Tables Generator.This issue affects Data Tables Generator: from n/a through 1.10.25.
Affected versions
max 1.10.26.
Status
vulnerable
Jan 03, 2025

Data Tables Generator by Supsystic # CVE-2024-56253

CVE, Research URL

CVE-2024-56253

Date
Jan 02, 2025
Research Description
Missing Authorization vulnerability in supsystic Data Tables Generator by Supsystic data-tables-generator-by-supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Data Tables Generator by Supsystic: from n/a through <= 1.10.36.
Affected versions
max 1.10.37.
Status
vulnerable
Dec 11, 2025

Data Tables Generator by Supsystic # CVE-2025-12089

CVE, Research URL

CVE-2025-12089

Date
Nov 13, 2025
Research Description
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cleanCache() function in all versions up to, and including, 1.10.45. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Affected versions
max 1.10.46.
Status
vulnerable
Jun 16, 2026

Data Tables Generator by Supsystic # ea026d6d7035f2d870a54c83ecf6e7dc2a5c2762

Date
Feb 08, 2021
Research Description
Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.9.97 WordPress Data Tables Generator by Supsystic plugin <= 1.9.96 - Stored Cross-Site Scripting (XSS) vulnerability Stored Cross-Site Scripting (XSS) vulnerability found by Erik David Martin in WordPress Data Tables Generator by Supsystic plugin (versions <= 1.9.96).
Affected versions
max 1.9.97.
Status
vulnerable

Data Tables Generator by Supsystic # 1cda2a7a-312b-456b-af4b-5e8992afaa93

Date
-
Research Description
Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.9.92 Data Tables Generator By Supsystic &lt; 1.9.92 - CSRF to Stored XSS, Data Table Creations, Settings Modification The Data Tables Generator by Supsystic WordPress plugin was affected by a CSRF to Stored XSS, Data Table Creations, Settings Modification security vulnerability.
Affected versions
max 1.9.92.
Status
vulnerable

Data Tables Generator by Supsystic # 703501c3265770c19ad2f11e7b0ec6ca3adaf90f

Date
Feb 08, 2021
Research Description
Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.9.97 WordPress Data Tables Generator by Supsystic plugin <= 1.9.96 - SQL injection (SQLi) vulnerability SQL injection (SQLi) vulnerability found by Erik David Martin in WordPress Data Tables Generator by Supsystic plugin (versions <= 1.9.96).
Affected versions
max 1.9.97.
Status
vulnerable

Data Tables Generator by Supsystic # afb38f74-21ab-46bb-aa9f-bdd98baeecd3

Date
-
Research Description
Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.9.92 Data Tables Generator By Supsystic &lt; 1.9.92 - Authenticated Stored XSS The Data Tables Generator by Supsystic WordPress plugin was affected by an Authenticated Stored XSS security vulnerability.
Affected versions
max 1.9.92.
Status
vulnerable

Data Tables Generator by Supsystic # 117bb262-133d-4117-b279-b5483efb6810

Date
-
Research Description
Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.10.0 wpscan.com
Affected versions
max 1.10.0.
Status
vulnerable

Data Tables Generator by Supsystic # 56e6afec-e337-432e-a879-99f46547c241

Date
-
Research Description
Data Tables Generator by Supsystic [data-tables-generator-by-supsystic] < 1.10.1 Data Tables Generator by Supsystic &lt; 1.10.1 - Authenticated Stored Cross-Site Scripting (XSS) The &quot;Editor&quot; tab under the &quot;Tables&quot; section is vulnerable to stored XSS. It is possible to store XSS in all input fields as the code does not sanitise any of the user input.
Affected versions
max 1.10.1.
Status
vulnerable
Oct 11, 2026

Data Tables Generator by Supsystic # CVE-2026-96648

CVE, Research URL

CVE-2026-96648

Date
Oct 10, 2026
Research Description
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell 'data' Value via updateRows Action in all versions up to, and including, 1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable by Subscriber-level users when an administrator has added their role to the plugin's 'access_roles' setting, which is a documented and explicitly supported plugin feature that grants lower-privileged users access to the dtgs_nonce required to reach the vulnerable updateRows action handler.
Affected versions
max 1.15.3.
Status
vulnerable