Description
The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages.
Published: 2026-07-28
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Tablesome Table WordPress plugin fails to perform authentication, capability, or nonce checks in one of its AJAX actions, allowing anyone with network access to create new published posts or overwrite existing posts and pages. This lack of authorization control means an attacker can deface a site, inject spam or malicious content, and alter the integrity of published material without any credentials.

Affected Systems

Any installation of Tablesome Table WordPress plugin with a version earlier than 1.1.31 is affected. The vulnerability exists in all earlier releases of the plugin regardless of the site's configuration or user roles.

Risk and Exploitability

The CVSS score of 7.5 indicates a high‑severity vulnerability, while the very low EPSS score of less than 1% suggests that exploitation is unlikely but still possible. Based on the description, the likely attack vector is an unauthenticated HTTP POST to the specific AJAX endpoint. The vulnerability is not listed in the CISA KEV catalog, but the potential for widespread defacement makes timely remediation advisable.

Generated by OpenCVE AI on August 4, 2026 at 13:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Tablesome Table plugin to version 1.1.31 or later.
  • If an upgrade is not possible at this time, block or restrict access to the vulnerable AJAX endpoint (for example, deny POST requests to /wp-admin/admin-ajax.php with the offending action parameter using a web‑application firewall).
  • Audit all site content for unauthorized posts or modifications and remove any that were added or altered without proper authorization.

Generated by OpenCVE AI on August 4, 2026 at 13:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Tablesome
Tablesome tablesome Table
Wordpress
Wordpress wordpress
Vendors & Products Tablesome
Tablesome tablesome Table
Wordpress
Wordpress wordpress

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages.
Title Tablesome < 1.1.31 - Unauthenticated Post Creation and Modification
References

Subscriptions

Tablesome Tablesome Table
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-28T13:16:39.290Z

Reserved: 2026-07-07T09:00:38.166Z

Link: CVE-2026-14924

cve-icon Vulnrichment

Updated: 2026-07-28T13:15:29.141Z

cve-icon NVD

Status : Deferred

Published: 2026-07-28T07:16:41.507

Modified: 2026-07-28T16:07:15.840

Link: CVE-2026-14924

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:15:03Z

Weaknesses