Beveiligingsadvies

CVE-2025-2939

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-06-03 02:27:34
Laatst bijgewerkt 2026-04-08 17:06:18
Toegewezen door Wordfence
CVSS-score 5.6
Status PUBLISHED

Beschrijving

The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute arbitrary functions, though it does not allow user supplied parameters only single functions can be called so the impact is limited.