vendor:
WordPress Plugin Ninja Tables
by:
Akash Rajendra Patil
5.5
CVSS
MEDIUM
Stored Cross-Site Scripting (XSS)
CWE
Product Name: WordPress Plugin Ninja Tables
Affected Version From: 4.1.2007
Affected Version To: 4.1.2007
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
2021
WordPress Plugin Ninja Tables 4.1.7 – Stored Cross-Site Scripting (XSS)
The vulnerability allows an attacker to store malicious JavaScript payload in the database which gets executed when triggered, resulting in a pop-up.
Mitigation:
Update to the latest version of Ninja Tables plugin.