Junglewise Threat Intelligence

CVE-2026-66597: wpDataTables unauthenticated cross-site scripting

CVE-2026-66597 · Severity: high · CVSS 7.1 · Published 2026-08-20

Vendors: TMS.

Executive brief

wpDataTables is a popular WordPress plugin used to create and display data tables on websites. An unauthenticated cross-site scripting (XSS) vulnerability in versions 6.5.1.4 and earlier allows attackers to inject malicious scripts that can steal visitor data, hijack user accounts, or redirect users to phishing sites without requiring authentication or administrative access.

Technical details

This is an unauthenticated reflected or stored cross-site scripting (XSS) vulnerability in wpDataTables plugin versions up to 6.5.1.4. The vulnerability exists due to insufficient input validation or output encoding in the plugin's code, allowing attackers to inject arbitrary JavaScript. The attack can be initiated by an unauthenticated user by crafting a malicious link or form submission, though user interaction (clicking a link or visiting a crafted page) is required for successful exploitation. An attacker can steal session cookies, perform actions on behalf of the victim, harvest credentials, or compromise site functionality. The vulnerability was patched in version 6.5.1.5.

Affected products

  • TMS wpDataTables <= 6.5.1.4

Timeline

  • 2026-08-20: disclosed
  • 2026-08-19: patched: Version 6.5.1.5 patched the vulnerability
  • 2026-08-19: advisory: Patchstack published advisory and issued mitigation rule

References