Incorrect Authorization in WP Table Builder Plugin for WordPress
CVE-2026-6922
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 September 2026
What is CVE-2026-6922?
The WP Table Builder plugin for WordPress contains a vulnerability that allows authenticated users with subscriber-level access or higher to manipulate posts, pages, and custom post types. This is due to an operator precedence flaw in the post-type guard within the trash_table_bulk() and restore_table_bulk() functions. The guard fails to activate, and the permission callback inadequately checks only for plugin role membership, neglecting necessary per-post-type or ownership verifications. Consequently, attackers can exploit this weakness to trash or restore arbitrary posts by providing any post IDs.
Affected Version(s)
WP Table Builder – Drag & Drop Table Builder 0 <= 2.2.1