Incorrect Authorization in WP Table Builder Plugin for WordPress
CVE-2026-6922

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2026

What is CVE-2026-6922?

The WP Table Builder plugin for WordPress contains a vulnerability that allows authenticated users with subscriber-level access or higher to manipulate posts, pages, and custom post types. This is due to an operator precedence flaw in the post-type guard within the trash_table_bulk() and restore_table_bulk() functions. The guard fails to activate, and the permission callback inadequately checks only for plugin role membership, neglecting necessary per-post-type or ownership verifications. Consequently, attackers can exploit this weakness to trash or restore arbitrary posts by providing any post IDs.

Affected Version(s)

WP Table Builder – Drag & Drop Table Builder 0 <= 2.2.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Quốc Huy (jtwings)
.