Junglewise Threat Intelligence

CVE-2026-54825: wpDataTables wpDataTables unauthenticated SQL injection

CVE-2026-54825 · Severity: critical · CVSS 9.3 · Published 2026-06-26

Technologies: wpDataTables.

Executive brief

wpDataTables is a popular WordPress plugin used to create and manage complex tables and charts. A security flaw allows unauthenticated attackers to interact directly with the website's database. This could lead to the theft of sensitive customer information, unauthorized access to site data, or disruption of website operations.

Technical details

An unauthenticated SQL injection vulnerability exists in the wpDataTables plugin for WordPress (versions <= 7.4). The flaw is caused by improper neutralization of special elements used in an SQL command (CWE-89) within the plugin's logic. A remote, unauthenticated attacker can exploit this by sending specially crafted network requests to the affected site. Successful exploitation allows the attacker to bypass authentication, extract sensitive data from the database, or potentially modify database records. The issue is resolved in version 7.4.1.

Affected products

  • wpDataTables wpDataTables <= 7.4

Timeline

  • 2026-05-31: other: Reported by Expatch
  • 2026-06-17: advisory: Patchstack advisory published
  • 2026-06-26: disclosed: NVD publication date
  • 2026-06-26: patched: Patch confirmed available in version 7.4.1

References