CVE-2025-2939
EUVD-2025-1674303.06.2025, 03:15
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute arbitrary functions, though it does not allow user supplied parameters only single functions can be called so the impact is limited.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| wpmanageninja | ninja_tables | 𝑥 < 5.0.19 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References