The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute arbitrary functions, though it does not allow user supplied parameters only single functions can be called so the impact is limited.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Thu, 10 Jul 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpmanageninja
Wpmanageninja ninja Tables |
|
CPEs | cpe:2.3:a:wpmanageninja:ninja_tables:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wpmanageninja
Wpmanageninja ninja Tables |
Tue, 03 Jun 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 03 Jun 2025 03:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute arbitrary functions, though it does not allow user supplied parameters only single functions can be called so the impact is limited. | |
Title | Ninja Tables – Easy Data Table Builder <= 5.0.18 - Unauthenticated PHP Object Injection to Limited Remote Code Execution | |
Weaknesses | CWE-502 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-06-03T02:27:34.986Z
Updated: 2025-06-03T14:51:37.647Z
Reserved: 2025-03-28T17:36:43.707Z
Link: CVE-2025-2939

Updated: 2025-06-03T14:51:22.428Z

Status : Analyzed
Published: 2025-06-03T03:15:27.137
Modified: 2025-07-10T14:20:31.850
Link: CVE-2025-2939

No data.