What the vulnerability does
01Description
A vulnerability classified as problematic has been found in Easy Table Plugin 1.6. This affects an unknown part of the file /wordpress/wp-admin/options-general.php. The manipulation with the input "><script>alert(1)</script> leads to basic cross site scripting. It is possible to initiate the attack remotely.
Explanation of Vulnerability in Simple Terms
02Summary
The Easy Table Plugin contains a cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject malicious scripts into table data. The vulnerability requires user interaction—typically a victim must view a page containing the injected content. The flaw affects data integrity but does not expose sensitive information or disrupt site availability.
What an attacker can do
03Attacker Capabilities
Inject malicious scripts that execute in the browser of users viewing affected tables.
Potential impact on your site
04Site Impact
Authenticated users with low privileges can deface table content or steal session cookies from site visitors viewing those tables.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege account (e.g., contributor or subscriber) and a victim must view the page with injected content.
Key dates
06Disclosure timeline
June 29, 2022
CVE published
April 15, 2025
Record updated