Impact
The vulnerability is caused by a logic flaw in the post‑type guard of the bulk trash and restore functions, allowing the guard to never block the operation. Combined with a permission callback that only checks overall plugin role membership, an authenticated user with subscriber or higher privileges can provide arbitrary post IDs in the 'ids' parameter and delete or restore any post, page or custom post type. This results in unauthorized content modification.
Affected Systems
The issue affects the WordPress plugin WP Table Builder – Drag & Drop Table Builder in all releases up to and including version 2.2.1.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity risk. With no EPSS score available and the vulnerability not listed in CISA KEV, formal exploitation evidence is lacking, but the attack can be executed by a legitimate subscriber simply by sending a crafted request to the bulk endpoints. The lack of per‑post or ownership checks removes any meaningful barrier to exploitation.
OpenCVE Enrichment