Junglewise Threat Intelligence

CVE-2026-57672: Melograno Venture Studio wpDataTables unauthenticated XSS

CVE-2026-57672 · Severity: high · CVSS 7.1 · Published 2026-07-02

Technologies: Melograno Venture Studio wpDataTables.

Executive brief

wpDataTables is a popular WordPress plugin used to create and manage complex tables and charts. A security flaw allows unauthenticated attackers to inject malicious scripts into the website, which are then executed in the browsers of other visitors. This could lead to unauthorized actions being performed on behalf of site administrators, theft of session information, or redirection of users to malicious websites.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the wpDataTables plugin for WordPress (versions 6.5.1.1 and below) due to improper neutralization of user-supplied input (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary web scripts. While the attack is unauthenticated, successful exploitation requires user interaction, typically from a privileged user (e.g., an administrator) clicking a malicious link or viewing a specific page. If successful, the attacker can execute scripts in the context of the victim's browser session, potentially leading to session hijacking or site defacement. The issue is resolved in version 6.5.1.2.

Affected products

  • Melograno Venture Studio wpDataTables <= 6.5.1.1

Timeline

  • 2026-06-22: disclosed: Reported by Nguyen Ba Khanh
  • 2026-06-30: advisory: Patchstack published advisory
  • 2026-07-02: advisory: NVD published CVE-2026-57672
  • 2026-06-30: patched: Version 6.5.1.2 released

References