PatchSiren cyber security CVE debrief
CVE-2026-96648 supsysticcom CVE debrief
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell 'data' Value through the updateRows Action in versions up to and including 1.15.1. This vulnerability allows authenticated attackers with subscriber-level access or higher to inject arbitrary web scripts into pages, which execute when a user accesses an injected page. However, exploitation requires an administrator to have added the attacker's role to the plugin's 'access_roles' setting, a documented feature granting lower-privileged users access to the dtgs_nonce required for the vulnerable updateRows action handler.
- Vendor
- supsysticcom
- Product
- Data Tables Generator by Supsystic
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
WordPress administrators and defenders responsible for securing plugins should assess exposure to this vulnerability. Specifically, those with subscriber-level users who have been granted elevated access via the 'access_roles' setting in the Data Tables Generator by Supsystic plugin should verify the presence of this vulnerability and take immediate action to restrict access and ensure proper input sanitization and output escaping.
Why it matters
CVE-2026-96648 is a Stored Cross-Site Scripting vulnerability in the Data Tables Generator by Supsystic plugin for WordPress. Defenders should prioritize verification of exposure, restrict access to the vulnerable action handler, and ensure proper input sanitization and output escaping to prevent exploitation.
- Defenders must verify if subscriber-level users have been granted access to the dtgs_nonce required for the updateRows action handler.
- Successful exploitation allows authenticated attackers to inject arbitrary web scripts into pages.
- Defenders need to ensure proper input sanitization and output escaping for table cell 'data' values.
- Remediation priority is high for WordPress installations with exposed versions and elevated subscriber access.
Technical summary
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell 'data' Value through the updateRows Action in versions up to and including 1.15.1. This is due to insufficient input sanitization and output escaping. An attacker must have subscriber-level access or higher and have their role added to the plugin's 'access_roles' setting by an administrator.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their WordPress installations, especially if subscriber-level users have been granted elevated access via the 'access_roles' setting. Immediate action is required to restrict access to the updateRows action handler and ensure proper input sanitization and output escaping.
Recommended defensive actions
- Verify the version of Data Tables Generator by Supsystic and upgrade to a patched version if necessary.
- Restrict access to the updateRows action handler to prevent unauthorized users from injecting malicious scripts.
- Ensure proper input sanitization and output escaping for table cell 'data' values.
- Monitor for suspicious activity related to the plugin's functionality.
- Perform a thorough review of the plugin's 'access_roles' setting to ensure that only authorized users have access to the dtgs_nonce.
- Conduct a security audit of the WordPress installation to identify potential vulnerabilities.
- Implement additional monitoring and logging to detect potential exploitation attempts.
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, affected versions, and references to code locations. However, there is limited information on exploitation or specific attack scenarios.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-96648 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-96648
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-96648 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-96648
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Data Tables Generator by Supsystic <= 1.15.1 - Authenticated (Subscriber+) Stored Cross-Site Scr
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/96xxx/CVE-2026-96648.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/data-tables-generator-by-supsystic/tags/1.15.0/src/SupsysticTables/Tables/Model/Tables.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/data-tables-generator-by-supsystic/tags/1.15.0/src/SupsysticTables/Tables/views/shortcode.twig
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/data-tables-generator-by-supsystic/tags/1.15.0/src/SupsysticTables/Tables/Controller.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/data-tables-generator-by-supsystic/tags/1.15.0/src/SupsysticTables/Core/BaseController.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/data-tables-generator-by-supsystic/tags/1.15.0/src/SupsysticTables/Core/Module.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/data-tables-generator-by-supsystic/
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/changeset/3721225/data-tables-generator-by-supsystic/trunk/src/SupsysticTables/Tables/Model/Tables.php
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.