Skip to main content

CVE-2024-0591: wpDataTables Plugin XSS Vulnerability

CVE-2024-0591 is a reflected cross-site scripting vulnerability in wpDataTables WordPress plugin affecting versions up to 3.4.2.2. Attackers can inject malicious scripts via the A parameter. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2024-0591 Overview

CVE-2024-0591 is a Reflected Cross-Site Scripting (XSS) vulnerability [CWE-79] in the wpDataTables plugin for WordPress. The flaw affects all versions up to and including 3.4.2.2. Attackers can inject arbitrary JavaScript through the A parameter because the plugin fails to properly sanitize input and escape output. Exploitation requires an unauthenticated attacker to trick a user into clicking a crafted link. Successful exploitation executes attacker-controlled script in the victim's browser session under the affected WordPress site's origin.

Critical Impact

Reflected XSS enables session hijacking, credential theft, and administrative account takeover when an authenticated administrator clicks a malicious link.

Affected Products

  • wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin
  • All versions up to and including 3.4.2.2
  • WordPress installations by vendor tms-outsource

Discovery Timeline

  • 2024-03-13 - CVE-2024-0591 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-0591

Vulnerability Analysis

The wpDataTables plugin reflects the value of the A HTTP request parameter back into rendered page content without applying sufficient input sanitization or output escaping. This behavior violates the guidance defined in CWE-79: Improper Neutralization of Input During Web Page Generation.

An attacker crafts a URL that includes a JavaScript payload in the A parameter. When a victim requests that URL, the plugin embeds the raw payload in the HTTP response. The browser parses and executes the script in the context of the WordPress site's origin.

Because the vulnerable code path is reachable without authentication, any visitor who follows the malicious link becomes a delivery target. Impact scales with the victim's privilege level.

Root Cause

The plugin trusts user-supplied input from the A query parameter and writes it into HTML output without HTML-encoding special characters such as <, >, ", and '. Standard WordPress escaping functions such as esc_html(), esc_attr(), or wp_kses() are not applied at the sink.

Attack Vector

Exploitation follows a standard reflected XSS pattern. The attacker constructs a URL pointing at a vulnerable endpoint of the WordPress site, appending a payload to the A parameter. The URL is delivered through phishing email, chat, or malicious web content. When the target opens the link, script execution occurs in the browser under the site's origin, granting the attacker access to cookies, DOM data, and any actions the user is authorized to perform.

The vulnerability manifests in reflected user input written unescaped into the response body. See the Wordfence Vulnerability Report for additional technical detail.

Detection Methods for CVE-2024-0591

Indicators of Compromise

  • HTTP requests to WordPress endpoints containing the A query parameter with HTML tags, <script> fragments, javascript: URIs, or event handlers such as onerror= and onload=.
  • Referrer headers pointing to unfamiliar phishing or link-shortener domains preceding administrator sessions.
  • Unexpected creation of WordPress administrator accounts or plugin installations shortly after a privileged user clicked an external link.

Detection Strategies

  • Inspect web server and reverse proxy access logs for requests where the A parameter contains URL-encoded angle brackets (%3C, %3E) or common XSS payload strings.
  • Deploy web application firewall (WAF) rules that flag reflected XSS signatures against wpDataTables endpoints.
  • Correlate outbound browser telemetry with wpDataTables page loads to identify script execution originating from reflected input.

Monitoring Recommendations

  • Alert on wpDataTables plugin versions at or below 3.4.2.2 reported by asset inventory or vulnerability scanners.
  • Track WordPress administrative actions such as user creation, role changes, and plugin installations for anomalies following inbound traffic to wpDataTables URLs.
  • Monitor Content Security Policy (CSP) violation reports for inline script execution on pages that render wpDataTables output.

How to Mitigate CVE-2024-0591

Immediate Actions Required

  • Update the wpDataTables plugin to a version later than 3.4.2.2 on every WordPress site in the environment.
  • Audit administrative accounts and active sessions for signs of unauthorized activity created after March 13, 2024.
  • Instruct administrators to avoid clicking untrusted links to the WordPress site until patching is verified.

Patch Information

The vendor tms-outsource addressed the input sanitization defect in a plugin update tracked in the WordPress Trac Change Set. Install the fixed release from the WordPress plugin repository and confirm the version reported in the WordPress admin console is above 3.4.2.2.

Workarounds

  • Deploy a WAF rule that blocks or sanitizes requests containing script tags or event-handler attributes in the A parameter targeting wpDataTables endpoints.
  • Enforce a strict Content Security Policy that disallows inline scripts and restricts script sources to trusted origins.
  • Temporarily disable the wpDataTables plugin if patching cannot be performed immediately and the functionality is not business-critical.
bash
# Example WAF rule (ModSecurity) blocking script payloads in the A parameter
SecRule ARGS:A "@rx (?i)(<script|onerror=|onload=|javascript:)" \
    "id:1002024,phase:2,deny,status:403,\
    msg:'CVE-2024-0591 wpDataTables reflected XSS attempt blocked'"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.