CVE-2020-12076

EUVD-2020-4392
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
mitreCNA
9.6 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:R