Impact
The Tablesome Table WordPress plugin fails to perform authentication, capability, or nonce checks in one of its AJAX actions, allowing anyone with network access to create new published posts or overwrite existing posts and pages. This lack of authorization control means an attacker can deface a site, inject spam or malicious content, and alter the integrity of published material without any credentials.
Affected Systems
Any installation of Tablesome Table WordPress plugin with a version earlier than 1.1.31 is affected. The vulnerability exists in all earlier releases of the plugin regardless of the site's configuration or user roles.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑severity vulnerability, while the very low EPSS score of less than 1% suggests that exploitation is unlikely but still possible. Based on the description, the likely attack vector is an unauthenticated HTTP POST to the specific AJAX endpoint. The vulnerability is not listed in the CISA KEV catalog, but the potential for widespread defacement makes timely remediation advisable.
OpenCVE Enrichment