nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-2306 CVE-2026-2306
MEDIUM
Ninja Tables <= 5.2.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Table Creation
Record summary
CVE-2026-2306 has a selected CVSS score of 4.3 (medium).
Description
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation due to missing authorization checks on the `createFluentCartTable` function in all versions up to, and including, 5.2.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary Ninja Tables in the database which can lead to database pollution and resource exhaustion.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Ninja Tables – Easy Data Table BuilderBrowse techjewel / Ninja Tables – Easy Data Table BuilderDefault status: unaffected | CVE List | Through 5.2.6 | affected |
References
7plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/ninja-tables/tags/5.2.6/app/Modules/FluentCart/FluentCartModule.php plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/ninja-tables/tags/5.2.6/app/Modules/FluentCart/Handlers/FluentCartHandler.php plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/ninja-tables/trunk/app/Modules/FluentCart/FluentCartModule.php plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/ninja-tables/trunk/app/Modules/FluentCart/Handlers/FluentCartHandler.php plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3453522%40ninja-tables%2Ftrunk&old=3447894%40ninja-tables%2Ftrunk&sfp_email=&sfph_mail= wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/592d42eb-4025-44af-a519-672656ad8b0e?source=cve