CVE-2022-29432

WordPress wpDataTables plugin <= 2.1.27 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities

Multiple Authenticated (administrator or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in TMS-Plugins wpDataTables plugin <= 2.1.27 on WordPress via &data-link-text, &data-link-url, &data, &data-shortcode, &data-star-num vulnerable parameters.


We have discovered 1,311 live websites that are affected by CVE-2022-29432.

Run a Free Instant Scan




Affected Software

Product  Wpdatatables
Category Wordpress Plugins
Vulnerable Domains1,311 live websites (100% of Wpdatatables install base)
Vulnerable Versions
  • from 0 through 2.1.27
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - May 20, 2022
  • Updated - Feb 20, 2025

Credits

  • Vulnerability discovered by Ex.Mi (Patchstack)

Website Distribution by Country

Number of websites using CVE-2022-29432
United States494 websites



Germany111 websites
France67 websites
GB67 websites
Italy46 websites
Spain42 websites
Netherlands37 websites
Canada32 websites
Switzerland29 websites
South Africa29 websites

Website Distribution by TLD

Number of websites using CVE-2022-29432
.com459 websites
.org191 websites
.de62 websites
.co.uk38 websites
.it36 websites
.net35 websites
.fr30 websites
.nl28 websites
.pl22 websites
.ch22 websites

Websites affected by CVE-2022-29432

Top websites that are affected by CVE-2022-29432. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.hr Croatia**,***
******************.org United States**,***
**************.eu United States**,***
****.com United States**,***
****.org GB***,***
**.****.edu United States***,***
*******.*****.edu United States***,***
**********.org United States***,***
*********************.org United States***,***
**********.com United States***,***
See full domain list

FAQ

CVE-2022-29432 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Wpdatatables
A total of 1,311 websites have been identified as vulnerable to CVE-2022-29432, based on global website indexing conducted by WebTechSurvey.
The Wpdatatables is affected by the CVE-2022-29432 vulnerability.
Wpdatatables versions up to and including 2.1.27 are vulnerable to CVE-2022-29432.