WordPress Plugin Vulnerabilities

Tablesome < 1.1.31 - Unauthenticated Post Creation and Modification

Description

The plugin does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages.

Proof of Concept

Affects Plugins

Fixed in 1.1.31

References

Classification

Type
NO AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
Kim Dvash
Submitter
Kim Dvash
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-07-07 (about 21 days ago)
Added
2026-07-07 (about 20 days ago)
Last Updated
2026-07-07 (about 20 days ago)

Other