Description
The TableMaster for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.6. This is due to the plugin not restricting which URLs can be fetched when importing CSV data from a URL in the Data Table widget. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations, including localhost and internal network services, and read sensitive files such as wp-config.php via the 'csv_url' parameter.
Published: 2026-01-28
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Apply Patch
AI Analysis

Impact

The TableMaster for Elementor plugin for WordPress is vulnerable to Server‑Side Request Forgery in all versions up to 1.3.6. The flaw occurs because the plugin does not restrict the URLs that can be fetched when importing CSV data via the 'csv_url' parameter. An authenticated user with Author-level access and above can supply any URL, causing the plugin to perform web requests on their behalf. This allows the attacker to reach arbitrary locations, including localhost and internal network services, and read sensitive files such as wp-config.php. The weakness is a classic example of CWE‑918: Server‑Side Request Forgery.

Affected Systems

Vendor bloompixel offers TableMaster for Elementor – Advanced Responsive Tables for Elementor. All plugin releases up to and including version 1.3.6 are affected.

Risk and Exploitability

The CVSS score of 7.2 indicates a medium severity flaw. The EPSS score of less than 1% suggests that, at the time of analysis, exploitation is unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog. The attack vector requires an authenticated author‑level or higher attacker with access to the Data Table widget, who supplies a crafted 'csv_url' value. Once exploited, the attacker can read sensitive configuration files or access internal resources, leading to potential data exposure and compromise of the site’s integrity.

Generated by OpenCVE AI on April 20, 2026 at 20:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the TableMaster for Elementor plugin to version 1.3.7 or later, where the CSV import URL filtering has been implemented.
  • If an immediate update is not possible, disable the CSV import feature in the Data Table widget or remove the 'csv_url' parameter using a custom function to prevent arbitrary URL requests.
  • Restrict the capability of Author and higher roles to reduce the number of users who can access the widget, or apply stricter access controls through role‑management plugins.

Generated by OpenCVE AI on April 20, 2026 at 20:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 28 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 28 Jan 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Bloompixel
Bloompixel tablemaster For Elementor
Elementor
Elementor elementor
Wordpress
Wordpress wordpress
Vendors & Products Bloompixel
Bloompixel tablemaster For Elementor
Elementor
Elementor elementor
Wordpress
Wordpress wordpress

Wed, 28 Jan 2026 05:45:00 +0000

Type Values Removed Values Added
Description The TableMaster for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.6. This is due to the plugin not restricting which URLs can be fetched when importing CSV data from a URL in the Data Table widget. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations, including localhost and internal network services, and read sensitive files such as wp-config.php via the 'csv_url' parameter.
Title TableMaster for Elementor <= 1.3.6 - Authenticated (Author+) Server-Side Request Forgery via 'csv_url' Parameter
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Bloompixel Tablemaster For Elementor
Elementor Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:31:53.135Z

Reserved: 2025-12-12T20:18:16.786Z

Link: CVE-2025-14610

cve-icon Vulnrichment

Updated: 2026-01-28T20:50:18.827Z

cve-icon NVD

Status : Deferred

Published: 2026-01-28T06:15:48.457

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-14610

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-20T21:00:12Z

Weaknesses