5.6
CVE-2025-2939
- EPSS 0.1%
- Veröffentlicht 03.06.2025 02:27:34
- Zuletzt bearbeitet 10.07.2025 14:20:31
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
Ninja Tables – Easy Data Table Builder <= 5.0.18 - Unauthenticated PHP Object Injection to Limited Remote Code Execution
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute arbitrary functions, though it does not allow user supplied parameters only single functions can be called so the impact is limited.
Mögliche Gegenmaßnahme
Ninja Tables – Easy Data Table Builder: Update to version 5.0.19, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Ninja Tables – Easy Data Table Builder
Version
* - 5.0.18
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wpmanageninja ≫ Ninja Tables SwPlatformwordpress Version < 5.0.19
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.284 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 5.6 | 2.2 | 3.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.