WordPress Data Table Plugin Security Update Advisory

Overview

 

An update has been released to address vulnerability in the WordPress Data Tables plugin. Users of affected versions are advised to update to the latest version.

 

Affected Products

 

WordPress Data Tables plugin versions 6.3.1 or below

 

Resolved Vulnerabilities

 

SQL injection vulnerability via the ‘id_key’ parameter of the wdt_delete_table_row AJAX action in the WordPress Data Table plugin (CVE-2024-3820)

 

Vulnerability Patches

 

Vulnerability patches are available in the latest update. Please follow the instructions on the referenced sites to update to the latest version.

WordPress Data Table Plugin version 6.3.2

 

Referenced Sites

 

[1] CVE-2024-3820 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-3820

[2] wpDataTables – Tables & Table Charts (Premium) <= 6.3.1 – Unauthenticated SQL Injection

Https:// http://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpdatatables-2/wpdatatables-tables-table-charts-premium-631-unauthenticated-sql-injection