PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-96648 supsysticcom CVE debrief

The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell 'data' Value through the updateRows Action in versions up to and including 1.15.1. This vulnerability allows authenticated attackers with subscriber-level access or higher to inject arbitrary web scripts into pages, which execute when a user accesses an injected page. However, exploitation requires an administrator to have added the attacker's role to the plugin's 'access_roles' setting, a documented feature granting lower-privileged users access to the dtgs_nonce required for the vulnerable updateRows action handler.

Vendor
supsysticcom
Product
Data Tables Generator by Supsystic
CVSS
MEDIUM 6.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

WordPress administrators and defenders responsible for securing plugins should assess exposure to this vulnerability. Specifically, those with subscriber-level users who have been granted elevated access via the 'access_roles' setting in the Data Tables Generator by Supsystic plugin should verify the presence of this vulnerability and take immediate action to restrict access and ensure proper input sanitization and output escaping.

Why it matters

CVE-2026-96648 is a Stored Cross-Site Scripting vulnerability in the Data Tables Generator by Supsystic plugin for WordPress. Defenders should prioritize verification of exposure, restrict access to the vulnerable action handler, and ensure proper input sanitization and output escaping to prevent exploitation.

  • Defenders must verify if subscriber-level users have been granted access to the dtgs_nonce required for the updateRows action handler.
  • Successful exploitation allows authenticated attackers to inject arbitrary web scripts into pages.
  • Defenders need to ensure proper input sanitization and output escaping for table cell 'data' values.
  • Remediation priority is high for WordPress installations with exposed versions and elevated subscriber access.

Technical summary

The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell 'data' Value through the updateRows Action in versions up to and including 1.15.1. This is due to insufficient input sanitization and output escaping. An attacker must have subscriber-level access or higher and have their role added to the plugin's 'access_roles' setting by an administrator.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their WordPress installations, especially if subscriber-level users have been granted elevated access via the 'access_roles' setting. Immediate action is required to restrict access to the updateRows action handler and ensure proper input sanitization and output escaping.

Recommended defensive actions

  • Verify the version of Data Tables Generator by Supsystic and upgrade to a patched version if necessary.
  • Restrict access to the updateRows action handler to prevent unauthorized users from injecting malicious scripts.
  • Ensure proper input sanitization and output escaping for table cell 'data' values.
  • Monitor for suspicious activity related to the plugin's functionality.
  • Perform a thorough review of the plugin's 'access_roles' setting to ensure that only authorized users have access to the dtgs_nonce.
  • Conduct a security audit of the WordPress installation to identify potential vulnerabilities.
  • Implement additional monitoring and logging to detect potential exploitation attempts.

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description, affected versions, and references to code locations. However, there is limited information on exploitation or specific attack scenarios.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-96648 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-96648

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-96648 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-96648

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Data Tables Generator by Supsystic <= 1.15.1 - Authenticated (Subscriber+) Stored Cross-Site Scr

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/96xxx/CVE-2026-96648.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/data-tables-generator-by-supsystic/tags/1.15.0/src/SupsysticTables/Tables/Model/Tables.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/data-tables-generator-by-supsystic/tags/1.15.0/src/SupsysticTables/Tables/views/shortcode.twig

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/data-tables-generator-by-supsystic/tags/1.15.0/src/SupsysticTables/Tables/Controller.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/data-tables-generator-by-supsystic/tags/1.15.0/src/SupsysticTables/Core/BaseController.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/data-tables-generator-by-supsystic/tags/1.15.0/src/SupsysticTables/Core/Module.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/data-tables-generator-by-supsystic/

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/changeset/3721225/data-tables-generator-by-supsystic/trunk/src/SupsysticTables/Tables/Model/Tables.php

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.