CNNVD-202506-3426 Information

CNNVD ID

CNNVD-202506-3426

CVE-2025-2940

  • CNNVD Published: 2025-06-27

Description (Chinese)

WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress plugin Ninja Tables – Easy Data Table Builder 5.0.18及之前版本存在代码问题漏洞,该漏洞源于args[url]参数导致的服务端请求伪造,可能导致未经验证的攻击者向任意位置发起Web请求。

Description (English)

WordPress and WordPressplugin are products of WordPress. WordPress is a blog platform developed in the PHP language. The platform supports the installation of personal blogs on PHP and MySQL servers. WordPress plugin is an application plugin. WordPress plugin Ninja Tables – Easy Data Table Builder 5.0.18 and previous versions had a code loophole, which originated in args [url] parameters when the service-end request was forged and could lead to unverified attackers initiating Web requests at any location.

Hazard Level

Medium

Vulnerability Type

代码问题

Affected Vendor

WordPress

Published

2025-06-27

Last Modified

2026-02-24

References

https://plugins.trac.wordpress.org/browser/ninja-tables/tags/5.0.18/vendor/wpfluent/framework/src/WPFluent/Http/Client.php#L268 https://plugins.trac.wordpress.org/browser/ninja-tables/tags/5.0.19/vendor/wpfluent/framework/src/WPFluent/Http/Client.php https://plugins.trac.wordpress.org/browser/ninja-tables/trunk/vendor/wpfluent/framework/src/WPFluent/Http/Client.php#L268 https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3269692%40ninja-tables&new=3269692%40ninja-tables&sfp_email=&sfph_mail= https://www.wordfence.com/threat-intel/vulnerabilities/id/02480559-be5c-4d23-9e62-bb76fafb4f42?source=cve

Patch

https://wordpress.org/plugins/ninja-tables

Share on: