Sensitive Information Exposure in Table Manager Plugin for WordPress
CVE-2026-4126
4.3MEDIUM
What is CVE-2026-4126?
The Table Manager plugin for WordPress is susceptible to a vulnerability that allows authenticated users with Contributor-level access and higher to exploit the 'table_manager' shortcode. This shortcode inadequately sanitizes the 'table' attribute, which is essential for referencing database tables. The lack of an allowlist verification permits attackers to access arbitrary tables in the WordPress database, enabling them to extract sensitive information. The critical flaw lies in the shortcode handler, which concatenates user input with internal database query commands without sufficient validation.
Affected Version(s)
Table Manager 0 <= 1.0.0