plugin

Wp Table Manager Vulnerabilities

6 known security issues reported for the Wp Table Manager WordPress plugin. Most recent disclosed Feb 12, 2025.

3 medium

Running Wp Table Manager on your site? Check whether your installed version is affected.

Scan your site free

WP Table Manager [wp-table-manager] < 4.1.4

unknown

[en] The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thewptm_getFolders AJAX action in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary file names an...

Affected:
up to 4.1.4
Fixed in:
4.1.4
Disclosed:
Feb 12, 2025

CVE-2024-13374 on NVD →

WP Table Manager <= 4.1.3 - Missing Authorization to Authenticated (Subscriber+) Directory Traversal to Folder/File Name Disclosure

medium

The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thewptm_getFolders AJAX action in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary file names and dir...

CVSS:
4.3
Affected:
up to 4.1.3
Fixed in:
4.1.4
Disclosed:
Feb 11, 2025

CVE-2024-13374 on NVD →

WP Table Manager [wp-table-manager] < 3.5.3

unknown

[en] Missing Authorization vulnerability in JoomUnited WP Table Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Table Manager: from n/a through 3.5.2.

Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Jan 2, 2025

CVE-2022-47601 on NVD →

WP Table Manager [wp-table-manager] < 3.5.3

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in JoomUnited WP Table Manager plugin <= 3.5.2 versions.

Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Mar 29, 2023

CVE-2022-47602 on NVD →

WP Table Manager <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WP Table Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting parameter in versions up to, and including, 3.5.2 due to insufficient input sanitization and output escaping on table cell values. This makes it possible for authenticated attackers, with contributor-level permissions and above, to i...

CVSS:
6.4
Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Jan 27, 2023

CVE-2022-47602 on NVD →

WP Table Manager <= 3.5.2 - Missing Authorization

medium

The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.5.2
Fixed in:
3.5.3
Disclosed:
Jan 27, 2023

CVE-2022-47601 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database