CVE · High

CVE-2021-24197 — wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin [wpdatatables] < 3.4.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24197 wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin [wpdatatables] < 3.4.2 Improper Access Control High 8.1 < 3.4.2 3.4.2 2021-03-16

CVE-2021-24197

The wpDataTables plugin before version 3.4.2 suffers from an access control vulnerability in its premium edition that allows authenticated users with low privilege levels to manipulate the formdata[wdt_ID] parameter and view or modify data belonging to other users within the same table. An attacker exploiting this flaw could gain unauthorized access to and control over all user data present in affected tables by escalating their permissions beyond their intended scope. This vulnerability only impacts the premium version of the plugin, despite the shared plugin slug with the free version.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.