SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-14924

HIGH · CVSS 7.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

The Tablesome Table WordPress plugin prior to version 1.1.31 is vulnerable due to a lack of authentication and capability checks in its AJAX actions, enabling unauthenticated users to create new published posts and overwrite existing content. This vulnerability poses a significant risk of content manipulation and unauthorized access, making it critical for WordPress site administrators using this plugin to prioritize immediate updates. Organizations relying on this plugin should assess their exposure and implement the necessary patches to mitigate potential exploitation.

CVE
CVE-2026-14924
Severity
HIGH
CVSS
7.5
EPSS
0.25%
WordPress

Original NVD Description

The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages.