CVE-2020-12076

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
23/04/2020
Last modified:
29/04/2020

Description

The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:supsystic:data_tables_generator:*:*:*:*:*:wordpress:*:* 1.9.92 (excluding)