PT-2025-27071 · WordPress · The Ninja Tables

Published

2025-06-27

·

Updated

2025-07-02

·

CVE-2025-2940

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: The Ninja Tables – Easy Data Table Builder plugin for WordPress versions up to, and including, 5.0.18
Description: The issue allows unauthenticated attackers to make web requests to arbitrary locations originating from the web application. This can be used to query and modify information from internal services via the args[url] parameter.
Recommendations: For versions up to, and including, 5.0.18, consider disabling access to the args[url] parameter until a patch is available to prevent Server-Side Request Forgery attacks.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-2940

Affected Products

The Ninja Tables