CVE-2026-14924

HIGH

Tablesome < 1.1.31 - Unauthenticated Post Creation and Modification

Title source: cna
STIX 2.1

Description

The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages.

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/6cbb9796-5f9b-44b4-b814-176ed225b184/

Scores

CVSS v3 7.5
EPSS 0.0025
EPSS Percentile 16.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
None/Tablesome Table < 1.1.31
Published Jul 28, 2026
Tracked Since Jul 28, 2026