CVE-2019-20180

MEDIUM

TablePress 1.9.2 - Code Injection

Title source: llm
STIX 2.1

Description

The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with the application that opens the CSV file and not TablePress.

Scores

CVSS v3 6.8
EPSS 0.0274
EPSS Percentile 86.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1236
Status published
Products (1)
tablepress/tablepress < 1.9.2
Published Jan 09, 2020
Tracked Since Feb 18, 2026