Stored Cross-Site Scripting in Smart Table Builder for WordPress
CVE-2025-9126
6.4MEDIUM
What is CVE-2025-9126?
The Smart Table Builder plugin for WordPress has a vulnerability that allows for Stored Cross-Site Scripting through the 'id' parameter in all versions up to 1.0.1. Due to inadequate input sanitization and output escaping, authenticated attackers with Contributor-level access or higher can inject arbitrary web scripts into pages. These scripts execute when any user accesses the compromised page, posing significant security risks to the affected WordPress installations.
Affected Version(s)
Smart Table Builder * <= 1.0.1