Server-Side Request Forgery Vulnerability in TableMaster for Elementor Plugin by WordPress
CVE-2025-14610
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 January 2026
What is CVE-2025-14610?
The TableMaster for Elementor plugin for WordPress is exposed to a Server-Side Request Forgery vulnerability that affects all versions up to and including 1.3.6. This flaw arises from the inadequate restriction of URLs that can be fetched while importing CSV data through the Data Table widget. Authenticated attackers with Author-level access or higher can exploit this vulnerability to issue web requests to arbitrary destinations, including local services and internal networks. This access can lead to the unauthorized reading of sensitive files such as wp-config.php via the 'csv_url' parameter, which poses a significant security risk for affected sites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
TableMaster for Elementor β Advanced Responsive Tables for Elementor * <= 1.3.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved