Sensitive Information Exposure in Table Manager Plugin for WordPress
CVE-2026-4126

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 April 2026

What is CVE-2026-4126?

The Table Manager plugin for WordPress is susceptible to a vulnerability that allows authenticated users with Contributor-level access and higher to exploit the 'table_manager' shortcode. This shortcode inadequately sanitizes the 'table' attribute, which is essential for referencing database tables. The lack of an allowlist verification permits attackers to access arbitrary tables in the WordPress database, enabling them to extract sensitive information. The critical flaw lies in the shortcode handler, which concatenates user input with internal database query commands without sufficient validation.

Affected Version(s)

Table Manager 0 <= 1.0.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Itthidej Aramsri
.