← WordPress Vulnerabilities
WordPress security by component

TablePress

TablePress is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Jun 25, 2026; the highest CVE/CNA score is 7.1.

Plugin slug: tablepress

CVE-2026-56051: TablePress: Cross-site scripting

TablePress is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.3.1.

PublishedJun 25, 2026
Known safe version3.3.2
Safe version
Jun 25, 2026 CVE-2026-56051
TablePress: Cross-site scripting
TablePress is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.3.1.
3.3.2
CVE7.1
NVDPending
Nov 04, 2025 CVE-2025-12324
TablePress – Tables in WordPress made easy: Cross-site scripting
TablePress – Tables in WordPress made easy is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Aug 30, 2025 CVE-2025-9500
TablePress: Cross-site scripting
TablePress is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
May 23, 2025 CVE-2025-5096
TablePress: Cross-site scripting
TablePress is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 27, 2025 CVE-2025-2685
TablePress – Tables in WordPress made easy: Cross-site scripting
TablePress – Tables in WordPress made easy is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Oct 12, 2024 CVE-2024-9595
TablePress – Tables in WordPress made easy: Cross-site scripting
TablePress – Tables in WordPress made easy is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 07, 2024 CVE-2024-4354
TablePress – Tables in WordPress made easy: Server-side request forgery
TablePress – Tables in WordPress made easy is affected by server-side request forgery. Exploitation requires at least author-level access. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE6.4
NVDPending
Jan 30, 2024 CVE-2024-23825
Tablepress: A security weakness
Tablepress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE3.0
NVD4.9
Jan 09, 2020 CVE-2019-20180
Tablepress: A security weakness
Tablepress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.8
NVD6.8
Nov 17, 2017 CVE-2017-10889
Tablepress: A security weakness
Tablepress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3