CVE Database /
CVE-2024-3820
CVE · Critical
CVE-2024-3820 — wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin [wpdatatables] < 6.3.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-3820
|
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin [wpdatatables] < 6.3.2 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Critical
10.0
|
< 6.3.2
|
6.3.2 |
2024-05-31 |
—
|
CVE-2024-3820
The wpDataTables plugin versions 6.3.1 and earlier contain a SQL injection vulnerability in the wdt_delete_table_row AJAX action through the id_key parameter. The vulnerability stems from inadequate escaping of user input and improper SQL query preparation, permitting unauthenticated attackers to inject malicious SQL commands that can expose sensitive database information. This flaw is exclusive to the premium version of the plugin and has been patched in version 6.3.2.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings