Junglewise Threat Intelligence

CVE-2026-65474: WPManageNinja Ninja Tables sensitive data exposure

CVE-2026-65474 · Severity: medium · CVSS 5.3 · Published 2026-07-23

Vendors: WPManageNinja.

Executive brief

Ninja Tables is a popular WordPress plugin used to create and manage data tables on websites. A security vulnerability in versions 5.2.10 and earlier allows unauthenticated visitors to access sensitive system information that should be restricted. This exposure could provide attackers with technical details useful for planning more advanced attacks against the website.

Technical details

A sensitive data exposure vulnerability exists in the Ninja Tables plugin for WordPress (versions up to and including 5.2.10). The flaw, classified as CWE-497, allows an unauthenticated remote attacker to access sensitive system information due to improper authorization checks or exposure of internal data structures. This vulnerability can be exploited over the network without user interaction. Attackers can leverage the exposed information to gain insights into the system's configuration, potentially facilitating further exploitation. The issue is resolved in version 5.2.11.

Affected products

  • WPManageNinja Ninja Tables <= 5.2.10

Timeline

  • 2026-07-16: disclosed: Reported by Ananda Dhakal via Patchstack
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: patched: NVD publication and patch availability confirmed in version 5.2.11

References