HIGH🇵🇱 Wersja polska

CVE-2025-2940

CVSS 7.2v3.1pub. 2025-06-27upd. 2025-07-07

The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.18 via the args[url] parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
  • Wpmanageninja Ninja Tables

    APP
    Wpmanageninja
    < 5.0.19
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SSRFAuth Bypass
CWE
References

Related vulnerabilities

CVE-2025-2939MEDIUM5.6same product

The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all v...

CVE-2024-12772MEDIUM5.4same product

The Ninja Tables WordPress plugin before 5.0.17 does not sanitize and escape a parameter before outputting it...

CVE-2024-7304MEDIUM6.4same product

The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...

CVE-2024-23504MEDIUM5.3same product

Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/...

CVE-2024-23503MEDIUM4.3same product

Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/...