plugin

Tablepress Vulnerabilities

24 known security issues reported for the Tablepress WordPress plugin. Most recent disclosed Jun 25, 2026.

3 high 10 medium

Running Tablepress on your site? Check whether your installed version is affected.

Scan your site free

TablePress – Tables in WordPress made easy <= 3.3.1 - Reflected Cross-Site Scripting

medium

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execu...

CVSS:
6.1
Affected:
up to 3.3.1
Fixed in:
3.3.2
Disclosed:
Jun 25, 2026

CVE-2026-56051 on NVD →

Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter

medium

Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

CVSS:
6.1
Affected:
up to 3.0.2
Fixed in:
3.0.3
Disclosed:
Apr 30, 2026

CVE-2024-13362 on NVD →

TablePress &#8211; Tables in WordPress made easy [tablepress] < 3.2.5

unknown

[en] The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `table` shortcode attributes in all versions up to, and including, 3.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible f...

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Nov 4, 2025

CVE-2025-12324 on NVD →

TablePress – Tables in WordPress made easy <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

medium

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `table` shortcode attributes in all versions up to, and including, 3.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au...

CVSS:
6.4
Affected:
up to 3.2.4
Fixed in:
3.2.5
Disclosed:
Nov 3, 2025

CVE-2025-12324 on NVD →

TablePress <= 3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode_debug Parameter

medium

The TablePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shortcode_debug’ parameter in all versions up to, and including, 3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to injec...

CVSS:
6.4
Affected:
up to 3.2
Fixed in:
3.2.1
Disclosed:
Aug 29, 2025

CVE-2025-9500 on NVD →

TablePress <= 3.1.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Parameters

medium

The TablePress plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the 'data-caption', 'data-s-content-padding', 'data-s-title', and 'data-footer' data-attributes in all versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible fo...

CVSS:
6.4
Affected:
up to 3.1.2
Fixed in:
3.1.3
Disclosed:
May 22, 2025

CVE-2025-5096 on NVD →

TablePress – Tables in WordPress made easy <= 3.0.4 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘table-name’ parameter in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level ac...

CVSS:
6.4
Affected:
up to 3.0.4
Fixed in:
3.1
Disclosed:
Mar 26, 2025

CVE-2025-2685 on NVD →

TablePress &#8211; Tables in WordPress made easy [tablepress] < 2.4.3

unknown

[en] The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the table cell content in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level a...

Affected:
up to 2.4.3
Fixed in:
2.4.3
Disclosed:
Oct 12, 2024

CVE-2024-9595 on NVD →

TablePress <= 2.4.2 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the table cell content in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access...

CVSS:
6.4
Affected:
up to 2.4.2
Fixed in:
2.4.3
Disclosed:
Oct 11, 2024

CVE-2024-9595 on NVD →

PHPSpreadsheet Library < 2.3.0 - XXE Injection

high

The security scanner that prevents XXE attacks in the XLSX reader can be bypassed by slightly modifying the XML structure, utilizing white spaces. On servers that allow users to upload their own Excel (XLSX) sheets, Server files, and sensitive information can be disclosed by providing a crafted sheet.

CVSS:
7.5
Affected:
up to 2.4.2
Fixed in:
2.4.3
Disclosed:
Oct 7, 2024

CVE-2024-45293 on NVD →

TablePress &#8211; Tables in WordPress made easy [tablepress] < 2.4.3

unknown

[en] PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The security scanner responsible for preventing XXE attacks in the XLSX reader can be bypassed by slightly modifying the XML structure, utilizing white-spaces. On servers that allow users to upload their own Excel (XLSX) sheets, Server...

Affected:
up to 2.4.3
Fixed in:
2.4.3
Disclosed:
Oct 7, 2024

CVE-2024-45293 on NVD →

TablePress &#8211; Tables in WordPress made easy [tablepress] < 2.3.2

unknown

[en] The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3 via the get_files_to_import() function. This makes it possible for authenticated attackers, with author-level access and above, to make web requests to arbitrar...

Affected:
up to 2.3.2
Fixed in:
2.3.2
Disclosed:
Jun 7, 2024

CVE-2024-4354 on NVD →

TablePress – Tables in WordPress made easy <= 2.3 - Authenticated (Author+) Server-Side Request Forgery via DNS Rebind

medium

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3 via the get_files_to_import() function. This makes it possible for authenticated attackers, with author-level access and above, to make web requests to arbitrary loc...

CVSS:
6.4
Affected:
up to 2.3.1
Fixed in:
2.3.2
Disclosed:
Jun 6, 2024

CVE-2024-4354 on NVD →

TablePress <= 2.2.4 - Authenticated(Author+) Server Side Request Forgery(SSRF) via _get_import_files

high

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to and including 2.2.4 via the '_get_import_files' function. This makes it possible for authenticated attackers, with author access and above, to make web requests to arbitrary locations origi...

CVSS:
8.5
Affected:
up to 2.2.4
Fixed in:
2.2.5
Disclosed:
Jan 31, 2024

CVE-2024-23825 on NVD →

TablePress &#8211; Tables in WordPress made easy [tablepress] < 2.2.5

unknown

[en] TablePress is a table plugin for Wordpress. For importing tables, TablePress makes external HTTP requests based on a URL that is provided by the user. That user input is filtered insufficiently, which makes it is possible to send requests to unintended network locations and receive responses. On sites in a cloud e...

Affected:
up to 2.2.5
Fixed in:
2.2.5
Disclosed:
Jan 30, 2024

CVE-2024-23825 on NVD →

Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get

medium

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
2.0 – 2.1.4
Fixed in:
2.1.5
Disclosed:
Jul 18, 2023

CVE-2023-33999 on NVD →

TablePress <= 1.14 - Authenticated (Author+) CSV Injection

high

The TablePress plugin for WordPress is vulnerable to CSV Injection in versions up to and including 1.14 via the tablepress[data] value. This makes it possible for attackers with author level access and above to embed untrusted input into exported CSV files, which can result in code execution when these files are downlo...

CVSS:
8
Affected:
up to 1.14
Fixed in:
2.0
Disclosed:
Feb 1, 2020

CVE-2019-20180 on NVD →

TablePress &#8211; Tables in WordPress made easy [tablepress] < 2.0

unknown

[en] The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with the application that opens the CSV file and not TablePress.

Affected:
up to 2.0
Fixed in:
2.0
Disclosed:
Jan 9, 2020

CVE-2019-20180 on NVD →

TablePress &#8211; Tables in WordPress made easy [tablepress] < 1.8.1

unknown

[en] TablePress prior to version 1.8.1 allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vectors.

Affected:
up to 1.8.1
Fixed in:
1.8.1
Disclosed:
Nov 17, 2017

CVE-2017-10889 on NVD →

TablePress <= 1.8 - XML External Entity Injection

medium

TablePress prior to version 1.8.1 allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vectors.

CVSS:
4.3
Affected:
up to 1.8
Fixed in:
1.8.1
Disclosed:
Jul 4, 2017

CVE-2017-10889 on NVD →

TablePress &#8211; Tables in WordPress made easy [tablepress] < 3.1

unknown
Affected:
up to 3.1
Fixed in:
3.1

CVE-2025-2685 on NVD →

TablePress &#8211; Tables in WordPress made easy [tablepress] < 3.1.3

unknown
Affected:
up to 3.1.3
Fixed in:
3.1.3

CVE-2025-5096 on NVD →

TablePress &#8211; Tables in WordPress made easy [tablepress] < 3.2.1

unknown
Affected:
up to 3.2.1
Fixed in:
3.2.1

CVE-2025-9500 on NVD →

TablePress &#8211; Tables in WordPress made easy [tablepress] < 2.1.5

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 2.1.5
Fixed in:
2.1.5

CVE-2023-33999 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database