A critical security vulnerability has been discovered in the wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin, a popular plugin used by WordPress websites to create dynamic tables and charts.
The vulnerability, CVE-2024-3820, allows attackers to perform SQL injection via the ‘id_key’ parameter of the wdt_delete_table_row AJAX action. This flaw affects all versions of the plugin up to and including 6.3.1.
According to the WordFence blogs, the vulnerability arises due to insufficient escaping of user-supplied parameters and insufficient preparation on the existing SQL query.
This allows unauthenticated attackers to append additional SQL queries to already existing queries, potentially extracting sensitive information from the database.
It is important to note that this vulnerability only affects the premium version of the wpDataTables plugin.
Given the critical nature of this vulnerability, it poses a significant risk to websites using the affected versions of the wpDataTables plugin.
All-in-One Cybersecurity Platform for MSPs to provide full breach protection with a single tool, Watch a Full Demo
Attackers exploiting this flaw can gain unauthorized access to sensitive information stored in the database, leading to data breaches, loss of confidential information, and potential damage to the website’s reputation.
Website administrators using the wpDataTables plugin are strongly advised to:
The discovery of CVE-2024-3820 highlights the importance of regular security audits and updates for WordPress plugins.
Website administrators must remain vigilant and proactive in addressing vulnerabilities to protect their sites from potential attacks.
The wpDataTables plugin developers are expected to release a patch soon, and users are urged to apply it immediately to mitigate the risk.
For more information and updates on this vulnerability, stay tuned to security advisories and the official wpDataTables plugin website.
Get special offers from ANY.RUN Sandbox. Until May 31, get 6 months of free service or extra licenses. Sign up for free.
In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer overflow…
A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing attackers…
Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a cyberattack…
The ACRStealer malware, an infostealer disguised as illegal software such as cracks and keygens, has…
A security vulnerability in Nagios XI 2024R1.2.2, tracked as CVE-2024-54961, has been disclosed, allowing unauthenticated…
Ubiquiti Networks has issued an urgent security advisory (Bulletin 046) warning of multiple critical vulnerabilities…