CVE Database /
CVE-2021-24198
CVE · High
CVE-2021-24198 — wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin [wpdatatables] < 3.4.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24198
|
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin [wpdatatables] < 3.4.2 |
Improper Access Control |
High
8.1
|
< 3.4.2
|
3.4.2 |
2021-03-16 |
—
|
CVE-2021-24198
The wpDataTables plugin before version 3.4.2 contains an access control flaw that permits authenticated users with low privileges to delete data belonging to other users sharing the same table. An attacker can manipulate the id_key and id_val parameters to remove records from any user in the table, potentially compromising all user data within that table. This vulnerability applies exclusively to the premium edition of the plugin.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings