PT-2026-96665 · WordPress · Wp Table Builder

·

CVE-2026-6922

·

Published

2026-09-22

·

Updated

2026-09-29

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions WP Table Builder – Drag & Drop Table Builder versions prior to 2.2.2
Description Incorrect Authorization exists due to an operator precedence bug in the post-type guard within the trash table bulk() and restore table bulk() functions, which prevents the guard from executing. This is combined with a permission callback that verifies plugin role membership but fails to perform per-post-type or ownership checks. Consequently, authenticated users with subscriber-level access or higher can trash or restore any post, page, or custom post type on the site by providing arbitrary post IDs via the ids parameter.
Recommendations Update to a version newer than 2.2.1. As a temporary workaround, restrict access to the trash table bulk() and restore table bulk() functions to prevent unauthorized post manipulation.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6922

Affected Products

Wp Table Builder