CVE-2020-12075

The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.

Basic Information

CVE State
PUBLISHED
Reserved Date
April 23, 2020
Published Date
April 23, 2020
Last Updated
August 04, 2024
Vendor
n/a
Product
n/a
Description
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.
Tags
wordpress

CVSS Scores

CVSS v3.1

8.8 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v3.0

6.3 - MEDIUM

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CVSS v2.0

6.5

Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS Score

Score
0.42% (Percentile: 61.03%) as of 2025-05-12

Exploit Status

Exploited in the Wild
Yes (2020-03-24 07:10:05 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
Wordfence 2020-03-24 07:10:05 UTC

Timeline

  • Added to KEVIntel

  • CVE ID Reserved

  • CVE Published to Public