Sceawere
Vulnerability Detail
CVE-2026-96648UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in Data Tables Generator
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 3h ago
- Vendor
- supsysticcom
- Product
- Data Tables Generator by Supsystic
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell 'data' Value via updateRows Action in all versions up to, and including, 1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable by Subscriber-level users when an administrator has added their role to the plugin's 'access_roles' setting, which is a documented and explicitly supported plugin feature that grants lower-privileged users access to the dtgs_nonce required to reach the vulnerable updateRows action handler.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-10-10T05:16:40.533Z",
"pubdate": "2026-10-10T05:16:40.533Z",
"executiveSummary": "The Data Tables Generator by Supsystic plugin for WordPress (up to version 1.15.1) contains a Stored Cross-Site Scripting (XSS) vulnerability. This security flaw stems from insufficient input sanitization and output escaping within the table cell 'data' values processed by the 'updateRows' action.\nThe vulnerability allows authenticated users with subscriber-level access and above to inject arbitrary JavaScript payloads into table cells. When these pages are accessed by other users, including administrators, the malicious script executes within the context of their session.\nThe exploitation requirement is dependent on the administrator granting 'access_roles' permissions to lower-privileged users, a native feature of the plugin that provides the necessary 'dtgs_nonce'. This vulnerability poses a significant risk to the integrity and security of the WordPress installation, potentially leading to unauthorized administrative actions, session hijacking, or site-wide compromise depending on the target's privilege level.",
"technicalDetails": "The vulnerability resides within the 'updateRows' action handler of the Data Tables Generator by Supsystic plugin. The plugin fails to perform rigorous server-side validation or sanitization on the 'data' parameter submitted during row update operations. Consequently, users can inject malicious HTML and JavaScript payloads directly into the underlying table data structures.\nThe exploitation process follows a distinct flow: First, an authenticated attacker with a role explicitly permitted in the 'access_roles' configuration obtains the 'dtgs_nonce'. This nonce is required to bypass CSRF protections and interact with the 'updateRows' endpoint. Second, the attacker issues a specially crafted HTTP POST request to the plugin's backend, containing the malicious payload within the 'data' field of the table cells.\nBecause the plugin fails to sanitize the input before persistence and neglects to properly escape the output when the table is rendered, the payload is stored in the database. When any victim (such as an administrator or another authorized user) visits a page containing the infected table, the application renders the stored payload directly into the Document Object Model (DOM).\nThe browser executes the injected JavaScript within the victim's security context. This enables the attacker to perform actions on behalf of the victim, such as modifying plugin settings, creating new administrative accounts, or capturing session cookies. The impact is elevated if the victim possesses administrative privileges, as the XSS effectively grants the attacker equivalent control over the WordPress environment. This vulnerability affects all versions of the plugin up to and including 1.15.1 and remains persistent until the affected database entries are purged or the input is correctly sanitized via WordPress APIs, such as 'wp_kses_post' or 'esc_js', during the save and render cycles respectively."
}