PT-2026-96665 · WordPress · Wp Table Builder
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
WP Table Builder – Drag & Drop Table Builder versions prior to 2.2.2
Description
Incorrect Authorization exists due to an operator precedence bug in the post-type guard within the
trash table bulk() and restore table bulk() functions, which prevents the guard from executing. This is combined with a permission callback that verifies plugin role membership but fails to perform per-post-type or ownership checks. Consequently, authenticated users with subscriber-level access or higher can trash or restore any post, page, or custom post type on the site by providing arbitrary post IDs via the ids parameter.Recommendations
Update to a version newer than 2.2.1.
As a temporary workaround, restrict access to the
trash table bulk() and restore table bulk() functions to prevent unauthorized post manipulation.Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Table Builder