Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-14924— Tablesome < 1.1.31 - Unauthenticated Post Creation and Modification

Quick assessment

Affected
Unknown Tablesome Table
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress Tablesome Table是WordPress基金会的一款表格管理插件。 WordPress Tablesome Table 1.1.31之前版本存在授权问题漏洞,该漏洞源于未对AJAX操作进行身份验证、能力或随机数检查,允许未授权用户创建新公开帖子并覆盖任意现有帖子和页面。

AI Predicted 7.5 Difficulty: Easy EPSS 0.44% · P36

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
Unknown Tablesome Table < 1.1.31 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-14924

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Tablesome < 1.1.31 - Unauthenticated Post Creation and Modification
Source: CVE Program / CVE List V5
Vulnerability Description
The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
WordPress Tablesome Table 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WordPress Tablesome Table是WordPress基金会的一款表格管理插件。 WordPress Tablesome Table 1.1.31之前版本存在授权问题漏洞,该漏洞源于未对AJAX操作进行身份验证、能力或随机数检查,允许未授权用户创建新公开帖子并覆盖任意现有帖子和页面。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Tablesome Table 0 ~ 1.1.31 -

II. Public POCs for CVE-2026-14924

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-14924

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-14924 (1)

Same Patch Batch · Unknown · 2026-07-28 · 6 CVEs total

CVE-2026-14545 TrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via Password Res
CVE-2026-14870 Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS via form_id
CVE-2026-14821 Quiz And Survey Master < 11.1.5 - Contributor+ Arbitrary Template Deletion
CVE-2026-14819 Event Tickets < 5.28.4 - Editor+ Stored XSS via Ticket Move
CVE-2026-14926 FluentCart < 1.4.0 - Subscriber+ Subscription Payment-Method Tampering via IDOR

IV. Related Vulnerabilities

V. Comments for CVE-2026-14924

No comments yet


Leave a comment