Sceawere
Vulnerability Detail
CVE-2026-14877UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in Data Tables Generator
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 2h ago
- Vendor
- supsysticcom
- Product
- Data Tables Generator by Supsystic
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id attribute in all versions up to, and including, 1.12.03 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-10-10T06:16:41.750Z",
"pubdate": "2026-10-10T06:16:41.750Z",
"executiveSummary": "The Data Tables Generator by Supsystic plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability.\nThis security flaw, identified in all versions up to and including 1.12.03, arises from inadequate input sanitization and output escaping mechanisms within the plugin's data processing logic.\nAn attacker possessing contributor-level access or higher can exploit this vulnerability by injecting malicious web scripts into the 'id' attribute of table components.\nOnce the payload is stored, it will execute in the browser of any user—including administrators—who views the compromised page.\nThe primary impact of this vulnerability is the potential for session hijacking, credential theft, unauthorized administrative actions, or the redirection of users to malicious websites.\nThe vulnerability represents a critical risk to site integrity and user data confidentiality, as it bypasses standard security controls through the injection of unauthorized JavaScript code into the application's persistent storage.",
"technicalDetails": "The vulnerability is a classic Stored Cross-Site Scripting (XSS) flaw, stemming from the application's failure to properly sanitize user-supplied input or sanitize output rendered within the administrative or front-end interface.\nThe root cause resides in the handling of the 'id' attribute within the Data Tables Generator plugin. Because the application logic fails to validate or sanitize the character input provided by the user before storing it in the database, arbitrary HTML and JavaScript code can be successfully injected.\nThe attack flow begins when an authenticated attacker with at least contributor-level privileges creates or modifies a data table. During the configuration process, the attacker injects a malicious payload into the 'id' parameter field.\nSince the input is persisted without appropriate character encoding or context-aware output escaping, the malicious script becomes part of the stored record.\nWhenever a user, such as a site administrator, navigates to the page or post containing the injected table, the plugin retrieves the stored 'id' attribute and renders it directly into the HTML document object model (DOM) of the browser.\nThe browser, treating the malicious content as legitimate executable code, interprets and executes the JavaScript payload within the security context of the affected user's session.\nThis allows the attacker to perform operations on behalf of the victim, such as modifying plugin settings, creating new administrative accounts, or capturing session tokens via document.cookie access.\nThe vulnerability affects all versions of the Data Tables Generator by Supsystic up to and including version 1.12.03. Exploitation is limited to the local environment where the plugin is active and requires the attacker to have an active session with contributor-level privileges or higher, effectively limiting the attack surface to authenticated users rather than anonymous, unauthenticated remote attackers.\nPost-exploitation impact is severe, as the injected scripts can manipulate the site's front-end or back-end functionality, leading to a full compromise of the user's session or the facilitation of cross-site request forgery (CSRF) chains."
}