CVE-2026-14924
Received Received - Intake

Unauthenticated Post Creation and Modification in Tablesome WordPress Plugin

Vulnerability report for CVE-2026-14924, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: WPScan

Description

The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-28
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tablesome tablesome to 1.1.31 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Tablesome WordPress plugin before version 1.1.31. It allows unauthenticated users to create new published posts and overwrite existing posts or pages without proper authentication or authorization checks.

Detection Guidance

Check if your WordPress site uses Tablesome plugin version prior to 1.1.31. Inspect network traffic for unauthorized POST requests to /wp-admin/admin-ajax.php with actions like tablesome_create_post or tablesome_update_post. Look for unexpected post creations or modifications in the WordPress admin panel.

Impact Analysis

An attacker could exploit this to publish false or malicious content on your website, modify existing posts to spread misinformation, or deface your site. This could damage your reputation, mislead visitors, or violate trust.

Compliance Impact

This vulnerability could lead to unauthorized content changes, potentially violating data integrity requirements in GDPR or HIPAA. Unauthorized modifications may result in non-compliance with integrity and access control provisions.

Mitigation Strategies

Immediately update the Tablesome plugin to version 1.1.31 or later. If updating is not possible, disable the plugin until an update is available. Review all posts and pages for unauthorized changes and restrict WordPress admin access to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14924. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart