What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in WPManageNinja LLC Ninja Tables – Best Data Table Plugin for WordPress plugin <= 4.3.4 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in WPManageNinja LLC Ninja Tables – Best Data Table Plugin for WordPress plugin <= 4.3.4 versions.
Explanation of Vulnerability in Simple Terms
Ninja Tables contains a cross-site request forgery (CSRF) vulnerability that allows an attacker to perform unauthorized actions on behalf of a logged-in site administrator. The vulnerability requires the admin to visit a malicious webpage while authenticated to the WordPress site. An attacker can modify table data or settings without the admin's knowledge or consent.
What an attacker can do
Perform unauthorized actions on tables (create, modify, or delete) by tricking an authenticated admin into visiting a malicious page.
Potential impact on your site
Table data or configuration could be altered or deleted without your knowledge if an admin visits a malicious link while logged in.
Conditions required to exploit
Site admin must be logged into WordPress and visit an attacker-controlled webpage while the session is active.
Key dates
External resources
Related vulnerabilities