Description
Missing Authorization vulnerability in Imtiaz Rayhan Table Block by Tableberg tableberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Table Block by Tableberg: from n/a through <= 0.6.9.
Published: 2025-11-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the Table Block by Tableberg WordPress plugin that allows attackers to perform actions they should not be able to, by exploiting improperly configured access control levels. This weakness permits an attacker to access or manipulate plugin features and data that are intended to be restricted, potentially exposing protected content or allowing unauthorized content modifications. The issue is considered a broken access control problem and does not involve arbitrary code execution or denial of service.

Affected Systems

The affected product is the Table Block by Tableberg plugin developed by Imtiaz Rayhan. The vulnerability impacts all releases from the beginning of its availability through version 0.6.9. No specific sub‑versions are listed beyond the maximum affected version.

Risk and Exploitability

The CVSS base score of 4.3 indicates a medium severity vulnerability. The EPSS score of less than 1% suggests a very low probability of exploitation as of the current assessment. The vulnerability is not listed in the CISA KEV catalog. Attackers would most likely need to interact with the plugin via a web interface or authenticated session to manipulate access controls, so the attack vector is inferred to be web-based. Because the flaw is an authorization oversight rather than a code injection or buffer overflow, the risk to confidentiality, integrity, or availability depends on the data accessed or modified by the plugin.

Generated by OpenCVE AI on April 29, 2026 at 19:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Table Block by Tableberg plugin to a version newer than 0.6.9 if one is available.
  • If an update is not available, disable the plugin to eliminate the access control path.
  • Reconfigure WordPress role permissions to ensure only trusted users have access to the plugin’s configuration and management pages.

Generated by OpenCVE AI on April 29, 2026 at 19:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Wed, 10 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 21 Nov 2025 12:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Imtiaz Rayhan Table Block by Tableberg tableberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Table Block by Tableberg: from n/a through <= 0.6.9.
Title WordPress Table Block by Tableberg plugin <= 0.6.9 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:16.817Z

Reserved: 2025-11-21T11:21:12.145Z

Link: CVE-2025-66096

cve-icon Vulnrichment

Updated: 2025-12-10T20:47:44.532Z

cve-icon NVD

Status : Deferred

Published: 2025-11-21T13:15:51.037

Modified: 2026-04-27T18:16:35.350

Link: CVE-2025-66096

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T20:00:18Z

Weaknesses