CVE-2025-2939: Wpmanageninja Ninja Tables
Medium severity, CVSS 5.6. EPSS: 0.5% chance of exploitation in the next 30 days.
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute arbitrary functions, though it does not allow user supplied parameters only single functions can be called so the impact is limited.
Affected products
- Wpmanageninja Ninja Tables: before 5.0.19 (fixed in 5.0.19)
Published 2025-06-03. Last modified 2026-06-17.